---
id: CVE-2026-69112
title: >-
  Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability
  in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that
  fail to sanitize weight_map entries from sharded checkpoint indexes
summary: >-
  Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability
  in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that
  fail to sanitize weight_map entries from sharded checkpoint indexes. Attackers
  can…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H'
cwe:
  - CWE-22
vendor: accelerate
product: accelerate
affected:
  - accelerate <= 1.14.0
patched:
  - openshift_ai 2.25
published: '2026-08-10'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T20:32:21.400'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-69112'
references:
  - url: 'https://github.com/huggingface/accelerate/issues/4067'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/huggingface/accelerate/pull/4070'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/huggingface/accelerate/pull/4138'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/hugging-face-accelerate-path-traversal-and-dos-via-weight-map
    label: disclosure@vulncheck.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-69112'
  - url: 'https://github.com/huggingface/accelerate'
  - url: 'https://pypi.org/project/accelerate'
  - url: 'https://github.com/advisories/GHSA-4j2p-28q2-5m79'
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-69112.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-69112'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2513620'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-69112'
  - url: 'https://access.redhat.com/errata/RHSA-2026:65126'
tags:
  - nvd
  - osv
  - pip
  - csaf
  - vex
  - red-hat
  - ghsa
epss: 0.00148
epssPercentile: 0.04372
aliases:
  - GHSA-4j2p-28q2-5m79
  - PYSEC-2026-3804
ecosystem: pip
ingestedAt: '2026-09-08T19:08:49.634Z'
---

## Overview

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes. Attackers can supply relative paths with ../ sequences or absolute paths to read arbitrary files, or point shard entries at named pipes to cause indefinite blocking and denial of service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-69112)

Affected packages:

- `accelerate <= 1.14.0`

Patched in:

- `openshift_ai 2.25`

Source: https://osv.dev/vulnerability/GHSA-4j2p-28q2-5m79

## Vendor advisories

- **RHSA-2026:65126** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65126)
- **Red Hat VEX** · Important · affected: Lightspeed Core, Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI), Lightspeed Core, Red Hat Enterprise Linux AI (RHEL AI) 3 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-69112.json)
