Bug 2521805 - CVE-2026-66007 python-datasets: Datasets: Information disclosure via path traversal vulnerability [fedora-all]
Summary: CVE-2026-66007 python-datasets: Datasets: Information disclosure via path tra...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: python-datasets
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Alexander Lent
QA Contact:
URL:
Whiteboard: {"flaws": ["fd0db297-0c3f-4208-bb75-6...
Depends On:
Blocks: CVE-2026-66007
TreeView+ depends on / blocked
 
Reported: 2026-08-24 10:54 UTC by Ganesh
Modified: 2026-08-24 10:54 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ganesh 2026-08-24 10:54:28 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadata field is not properly validated before being joined to the dataset directory. Attackers can supply crafted file_name values with directory traversal sequences to read arbitrary local files, which are then embedded into output when save_to_disk or push_to_hub is called.


Note You need to log in before you can comment on or make changes to this bug.