1.1.2
4 years ago
3 days ago
Known vulnerabilities in the huggingface-hub package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
huggingface-hub is a Client library to download and publish models, datasets and other repos on the huggingface.co hub Affected versions of this package are vulnerable to Access Control Bypass such that a malicious repo on the Hub can overwrite any file on the disk when using How to fix Access Control Bypass? Upgrade | [,0.13.4) |