Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
6.9
CVE-2026-66007
- EPSS 0.52%
- Veröffentlicht 24.07.2026 14:58:10
- Zuletzt bearbeitet 17.08.2026 19:12:42
Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadata field is not properly validated before being joined to the dataset directory. Attackers can supply ...
6.6
CVE-2026-65010
- EPSS 0.13%
- Veröffentlicht 23.07.2026 17:55:52
- Zuletzt bearbeitet 23.07.2026 20:17:21
Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that allows local attackers to write arbitrary files by pre-planting symlinks at predictable output paths. Attackers can redirect archiv...
1