Executive brief
Hugging Face Datasets through version 5.0.0 contains a path traversal vulnerability in folder-based dataset builders where the file_name metadata field is not properly validated. This allows attackers to read arbitrary local files when a user loads a malicious dataset.
Affected products
- PyPI datasets
- Hugging Face datasets