Directory Traversal Affecting nemo package, versions <2.7.3-r29


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.19% (8th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-NEMO-20046698
  • published22 Sept 2026
  • disclosed10 Aug 2026

Introduced: 10 Aug 2026

CVE-2026-69112  (opens in a new tab)
CWE-22  (opens in a new tab)

How to fix?

Upgrade Chainguard nemo to version 2.7.3-r29 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream nemo package and not the nemo package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes. Attackers can supply relative paths with ../ sequences or absolute paths to read arbitrary files, or point shard entries at named pipes to cause indefinite blocking and denial of service.

CVSS Base Scores

version 3.1