Symlink Attack Affecting flash-attention package, versions [0,]


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.13% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-FLASHATTENTION-17971529
  • published14 Jul 2026
  • disclosed13 Jul 2026
  • creditUnknown

Introduced: 13 Jul 2026

NewCVE-2026-62239  (opens in a new tab)
CWE-59  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

flash-attention is a Flash Attention2 operator on Huawei Ascend 910A.

Affected versions of this package are vulnerable to Symlink Attack via the download_and_copy function in hopper/setup.py when extracting archives without validating symlinks or filtering tar members. An attacker can achieve arbitrary file writes with the privileges of the victim by pre-placing a symlink in the cache directory and triggering extraction during build time.

CVSS Base Scores

version 4.0
version 3.1