PT-2026-57903 · Dao Ailab+1 · Flash-Attention
CVSS v3.1
6.6
Medium
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
FlashAttention versions prior to 2.8.3.post1
Description
A symlink attack exists in the
download and copy() function within hopper/setup.py. The issue occurs because NVIDIA toolchain archives are extracted without validating symlinks or filtering tar members. A local attacker can place a symlink in the predictable cache directory to redirect extracted binaries to a location of their choice, allowing arbitrary file write with the privileges of the victim during the build process.Recommendations
Update FlashAttention to the version containing commit 0816ef1.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flash-Attention