CVE-2026-65010
Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that allows local attacker
CVSS
6.6
Medio
EPSS
0.1%
p3
KEV
—
Exploit Today
1
0-100
Publicado: 23 jul 2026 · Última mod.: 23 jul 2026 · CWE-61
0.1%EPSS · 30 días0.1%
2026-07-242026-07-25
Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that allows local attackers to write arbitrary files by pre-planting symlinks at predictable output paths. Attackers can redirect archive extraction to arbitrary filesystem locations in shared-cache environments, enabling overwrite of sensitive files and potential privilege escalation or code execution.
- github.comhttps://github.com/huggingface/datasets/commit/ad2d853ae2ce41d8068c23b44c2e29004312ccee
- github.comhttps://github.com/huggingface/datasets/issues/8296
- github.comhttps://github.com/huggingface/datasets/pull/8303
- www.vulncheck.comhttps://www.vulncheck.com/advisories/datasets-symlink-following-arbitrary-file-write-via-extractor-extract
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-174594.3 MED—
——0A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. Executing a manipulation can lead to symlink following. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.8hCVE-2026-120807.3 ALT3.7%
——1A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. This can occur either through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race. Successful exploitation allows the attacker to gain ownership of arbitrary root-owned files or directories, leading to root access. This vulnerability requires an external management layer (e.g., libvirt) to trigger the affected code path.5dCVE-2026-59674—3.0%
——1A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user to escalate to root.
This issue affects openSUSE Tumbleweed: from ? before 8.0.5-2.1; openSUSE Tumbleweed: from ? before 8.0.5-2.1.11dCVE-2026-398227.8 ALT14.3%
——4On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.13dCVE-2026-146993.3 BAJ3.8%
——1A weakness has been identified in zcaceres markdownify-mcp up to 1.1.0. The affected element is the function assertPathAllowed of the file src/Markdownify.ts. Executing a manipulation can lead to symlink following. The attack can only be executed locally. The pull request to fix this issue awaits acceptance.20dCVE-2026-534896.5 MED8.5%
——3containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via kubectl logs. This issue has been fixed in versions 2.3.2, 2.2.5 and 2.1.9.24d