Junglewise Threat Intelligence

CVE-2026-66007: Hugging Face Datasets path traversal in folder-based builders

CVE-2026-66007 · Severity: medium · CVSS 6.5 · Published 2026-07-24

Vendors: PyPI, Hugging Face.

Executive brief

Hugging Face Datasets through version 5.0.0 contains a path traversal vulnerability in folder-based dataset builders where the file_name metadata field is not properly validated. This allows attackers to read arbitrary local files when a user loads a malicious dataset.

Affected products

  • PyPI datasets
  • Hugging Face datasets

Related threats