A vulnerability was found in Hugging Face Datasets up to 5.00. It has been classified as problematic. Affected by this issue is the function
Extractor.extract of the component Symlink Handler. Performing a manipulation results in symlink following.
This vulnerability is cataloged as CVE-2026-65010. The attack must be initiated from a local position. There is no exploit available.
To fix this issue, it is recommended to deploy a patch.