---
id: CVE-2026-65010
title: Datasets Symlink-following Arbitrary File Write via Extractor.extract()
summary: >-
  Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following
  vulnerability in Extractor.extract() that allows local attackers to write
  arbitrary files by pre-planting symlinks at predictable output paths.
  Attackers can re…
severity: medium
cvss: 6.6
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-61
vendor: huggingface
product: datasets
affected:
  - datasets <= 5.00
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-23T19:09:45.573671Z'
exploitAvailable: true
published: '2026-07-23'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:20:14.218Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-65010'
references:
  - url: 'https://github.com/huggingface/datasets/issues/8296'
    label: Researcher Disclosure
  - url: 'https://github.com/huggingface/datasets/pull/8303'
    label: Pull Request
  - url: >-
      https://github.com/huggingface/datasets/commit/ad2d853ae2ce41d8068c23b44c2e29004312ccee
    label: Patch Commit
  - url: >-
      https://www.vulncheck.com/advisories/datasets-symlink-following-arbitrary-file-write-via-extractor-extract
tags:
  - cve.org
  - exploit-available
epss: 0.00173
epssPercentile: 0.05996
ingestedAt: '2026-10-01T15:48:17.859Z'
---

## Overview

Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that allows local attackers to write arbitrary files by pre-planting symlinks at predictable output paths. Attackers can redirect archive extraction to arbitrary filesystem locations in shared-cache environments, enabling overwrite of sensitive files and potential privilege escalation or code execution.

## Affected

- `datasets <= 5.00`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
