Skip to main content
EPSS 0.3%top 78%

CVE-2026-9856: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in huggingface huggingface/transformers

0
High
Published: 08/02/2026 (08/02/2026, 15:10:53 UTC)
Source: CVE Database V5
Vendor/Project: huggingface
Product: huggingface/transformers

Description

CVE-2026-9856 is a path traversal vulnerability in huggingface/transformers versions up to 5.8.0.dev0. It allows an attacker to write arbitrary files by exploiting improper validation of filenames derived from the chat_template dictionary keys in the save_pretrained() methods of PreTrainedTokenizerBase and ProcessorMixin. This can be triggered when a victim downloads and saves a maliciously crafted tokenizer or processor from a Hugging Face Hub repository. Multiple processors inheriting from ProcessorMixin are affected, including Idefics, Florence, Gemma, Phi, and Qwen-VL.

CVSS v3.0

Score 7.1high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
Low
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L

Affected software

huggingface

huggingface/transformers

transformers
pkg:pypi/transformers

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 15:21:02 UTC

Technical Analysis

The vulnerability resides in the save_pretrained() methods of PreTrainedTokenizerBase and ProcessorMixin in huggingface/transformers versions <=5.8.0.dev0. The methods use keys from the chat_template dictionary directly as filenames without proper sanitization, enabling path traversal. An attacker can publish a malicious Hugging Face Hub repository containing a crafted tokenizer_config.json file with attacker-controlled keys. When a victim downloads and saves the tokenizer or processor, these keys can cause files to be written outside the intended directory, leading to arbitrary file writes with attacker-controlled content. This affects multiple processors inheriting from ProcessorMixin, such as Idefics, Florence, Gemma, Phi, and Qwen-VL.

Potential Impact

An attacker can cause arbitrary file writes on the victim's system by exploiting the path traversal vulnerability during the save_pretrained() operation. This can lead to integrity violations by overwriting or creating files outside the intended directory. The vulnerability does not directly impact confidentiality or availability but poses a high risk to system integrity.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid downloading and saving tokenizers or processors from untrusted or unverified Hugging Face Hub repositories, especially those that may contain malicious tokenizer_config.json files. Monitor vendor channels for updates and apply patches promptly once released.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
@huntr_ai
Date Reserved
2026-05-28T15:41:24.076Z
Cvss Version
3.0
State
PUBLISHED

Threat ID: 6a6f66ddbf32cb7a34c8d5e6

Added to database: 08/02/2026, 15:48:45 UTC

Last enriched: 08/10/2026, 15:21:02 UTC

Last updated: 09/16/2026, 10:01:35 UTC

Views: 72

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses