flash-attention@1.0.0

Flash Attention2 operator on Huawei Ascend 910A.

Direct Vulnerabilities

Known vulnerabilities in the flash-attention package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Symlink Attack

flash-attention is a Flash Attention2 operator on Huawei Ascend 910A.

Affected versions of this package are vulnerable to Symlink Attack via the download_and_copy function in hopper/setup.py when extracting archives without validating symlinks or filtering tar members. An attacker can achieve arbitrary file writes with the privileges of the victim by pre-placing a symlink in the cache directory and triggering extraction during build time.

How to fix Symlink Attack?

A fix was pushed into the master branch but not yet published.

[0,)