flash-attention vulnerability

FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hopper/setup.py that extracts NVIDIA toolchain archives without validating symlinks or filtering tar members. A local attacker can pre-plant a symlink in the predictable cache directory to redirect extracted binaries to an attacker-chosen location, enabling arbitrary file write with victim privileges during build time.

Published 13 Jul 2026Updated 17 Sep 20265 sources
CVSS 5.3

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.