accelerate@1.15.0

Accelerate

Direct Vulnerabilities

Known vulnerabilities in the accelerate package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Directory Traversal

accelerate is an Accelerate

Affected versions of this package are vulnerable to Directory Traversal via load_checkpoint_in_model and load_checkpoint_and_dispatch through sharded-checkpoint weight_map handling in src/accelerate/utils/modeling.py. An attacker can make the loader read arbitrary files or block while opening special files by supplying shard names with ../ sequences, absolute paths, or other paths outside the checkpoint folder in a crafted checkpoint index. This lets a malicious checkpoint cause unintended file disclosure or denial of service when a user loads it in an affected Accelerate version.

How to fix Directory Traversal?

A fix was pushed into the master branch but not yet published.

[0,)
  • H
Deserialization of Untrusted Data

accelerate is an Accelerate

Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the parsing of checkpoints. An attacker can execute arbitrary code by convincing a user to open a specially crafted file or visit a malicious web page.

Note:

The report was rejected for being out of scope for the bug bounty program.

The vendor confirmed that no changes will be made and closed the report as informative.

How to fix Deserialization of Untrusted Data?

There is no fixed version for accelerate.

[0,)