Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3174 articles · 183287 vulns · 37/41 feeds (7d)
← Back to list
7.1
CVE-2026-9856PATCHED
huggingface · huggingface/transformers

Path Traversal in huggingface/transformers

Description

A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` dictionary are used directly as filenames without proper validation. An attacker can exploit this by publishing a malicious Hugging Face Hub repository with a crafted `tokenizer_config.json` file. When a victim downloads and saves the tokenizer or processor, the attacker-controlled keys can escape the intended save directory, enabling arbitrary file writes with attacker-controlled content. This vulnerability affects multiple processors inheriting from `ProcessorMixin`, including Idefics, Florence, Gemma, Phi, and Qwen-VL.

Affected Products

VendorProductVersions
huggingfacehuggingface/transformersunspecified

References

  • https://huntr.com/bounties/362824d5-fe18-40e8-a6cf-62277f97a170
  • https://github.com/huggingface/transformers/commit/eaaaf8494dd5386634ae37d1d122212fdc315be5

Related News (1 articles)

Tier C
VulDB19h ago
CVE-2026-9856 | Hugging Face transformers up to 5.9.x PreTrainedTokenizerBase/ProcessorMixin save_pretrained path traversal (EUVD-2026-52005)
→ No new info (linked only)
CVSS 3.17.1 HIGH
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
CISA KEV❌ No
Actively exploited❌ No
Patch available
5.10.0
CWECWE-22
PublishedAug 2, 2026
Trending Score25
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-44513EXP
Diffusers: `trust_remote_code` bypass via `custom_pipeline` and local custom components
Trending: 66
NONECVE-2026-66007
Datasets Path Traversal via Unsanitized file_name Metadata
Trending: 8
NONECVE-2026-65920
Diffusers Path Traversal via weight_map Arbitrary File Read
Trending: 7
NONECVE-2026-65010
Datasets Symlink-following Arbitrary File Write via Extractor.extract()
Trending: 7
NONECVE-2026-63086
text-generation-inference 3.3.7 SSRF via fetch_image in multimodal chat completions
Trending: 5

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 2, 2026
Patch Available
Aug 2, 2026
Discovered by ZDM
Aug 2, 2026