CVE-2026-9856: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in huggingface huggingface/transformers
CVE-2026-9856 is a path traversal vulnerability in huggingface/transformers versions up to 5.8.0.dev0. It allows an attacker to write arbitrary files by exploiting improper validation of filenames derived from the chat_template dictionary keys in the save_pretrained() methods of PreTrainedTokenizerBase and ProcessorMixin. This can be triggered when a victim downloads and saves a maliciously crafted tokenizer or processor from a Hugging Face Hub repository. Multiple processors inheriting from ProcessorMixin are affected, including Idefics, Florence, Gemma, Phi, and Qwen-VL.
AI Analysis
Technical Summary
The vulnerability resides in the save_pretrained() methods of PreTrainedTokenizerBase and ProcessorMixin in huggingface/transformers versions <=5.8.0.dev0. The methods use keys from the chat_template dictionary directly as filenames without proper sanitization, enabling path traversal. An attacker can publish a malicious Hugging Face Hub repository containing a crafted tokenizer_config.json file with attacker-controlled keys. When a victim downloads and saves the tokenizer or processor, these keys can cause files to be written outside the intended directory, leading to arbitrary file writes with attacker-controlled content. This affects multiple processors inheriting from ProcessorMixin, such as Idefics, Florence, Gemma, Phi, and Qwen-VL.
Potential Impact
An attacker can cause arbitrary file writes on the victim's system by exploiting the path traversal vulnerability during the save_pretrained() operation. This can lead to integrity violations by overwriting or creating files outside the intended directory. The vulnerability does not directly impact confidentiality or availability but poses a high risk to system integrity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid downloading and saving tokenizers or processors from untrusted or unverified Hugging Face Hub repositories, especially those that may contain malicious tokenizer_config.json files. Monitor vendor channels for updates and apply patches promptly once released.
CVE-2026-9856: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in huggingface huggingface/transformers
Description
CVE-2026-9856 is a path traversal vulnerability in huggingface/transformers versions up to 5.8.0.dev0. It allows an attacker to write arbitrary files by exploiting improper validation of filenames derived from the chat_template dictionary keys in the save_pretrained() methods of PreTrainedTokenizerBase and ProcessorMixin. This can be triggered when a victim downloads and saves a maliciously crafted tokenizer or processor from a Hugging Face Hub repository. Multiple processors inheriting from ProcessorMixin are affected, including Idefics, Florence, Gemma, Phi, and Qwen-VL.
CVSS v3.0
Score 7.1high
Affected software
huggingface
huggingface/transformers
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability resides in the save_pretrained() methods of PreTrainedTokenizerBase and ProcessorMixin in huggingface/transformers versions <=5.8.0.dev0. The methods use keys from the chat_template dictionary directly as filenames without proper sanitization, enabling path traversal. An attacker can publish a malicious Hugging Face Hub repository containing a crafted tokenizer_config.json file with attacker-controlled keys. When a victim downloads and saves the tokenizer or processor, these keys can cause files to be written outside the intended directory, leading to arbitrary file writes with attacker-controlled content. This affects multiple processors inheriting from ProcessorMixin, such as Idefics, Florence, Gemma, Phi, and Qwen-VL.
Potential Impact
An attacker can cause arbitrary file writes on the victim's system by exploiting the path traversal vulnerability during the save_pretrained() operation. This can lead to integrity violations by overwriting or creating files outside the intended directory. The vulnerability does not directly impact confidentiality or availability but poses a high risk to system integrity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid downloading and saving tokenizers or processors from untrusted or unverified Hugging Face Hub repositories, especially those that may contain malicious tokenizer_config.json files. Monitor vendor channels for updates and apply patches promptly once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- @huntr_ai
- Date Reserved
- 2026-05-28T15:41:24.076Z
- Cvss Version
- 3.0
- State
- PUBLISHED
Threat ID: 6a6f66ddbf32cb7a34c8d5e6
Added to database: 08/02/2026, 15:48:45 UTC
Last enriched: 08/10/2026, 15:21:02 UTC
Last updated: 09/16/2026, 10:01:35 UTC
Views: 72
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.