CVE-2026-9856: transformers: path traversal in save_pretrained() writes files

GHSA-xrqw-3rrv-vx5w HIGH
Published August 2, 2026
CISO Take

A path traversal flaw in Hugging Face `transformers` lets an attacker who publishes a malicious Hub repository control filenames written to disk when a victim saves a downloaded tokenizer or processor — `save_pretrained()` uses attacker-supplied `chat_template` dictionary keys directly as filenames, so a crafted key like `../../` sequences can escape the intended save directory and write attacker-controlled content anywhere the calling process has permissions. This is a supply-chain vector, not a remote network exploit: it triggers only when a developer or pipeline pulls a poisoned tokenizer/processor config from the Hub (including popular multimodal families — Idefics, Florence, Gemma, Phi, Qwen-VL) and calls `save_pretrained()`, but the payoff (arbitrary file write) is a classic primitive for turning into code execution — overwriting SSH `authorized_keys`, cron entries, or shell profiles. There's no CISA KEV listing, no public exploit or Nuclei template, and EPSS sits at 0.3% (78th percentile, low near-term exploitation likelihood), and CISA SSVC rates it TRACK — so this is not an emergency, but transformers underpins most self-hosted LLM/VLM pipelines, making the blast radius large if a malicious repo is adopted before detection. Action: upgrade `transformers` past the version incorporating fix commit `eaaaf8494dd5386634ae37d1d122212fdc315be5`, and until patched, treat any Hub repo not from a verified/trusted org as untrusted input — review `tokenizer_config.json`/`chat_template` contents before calling `save_pretrained()`, and run model-loading code with least-privilege filesystem access.

Sources: NVD EPSS ATLAS github.com huntr.com

What is the risk?

Moderate risk overall. Exploitability requires social-engineering-adjacent conditions (victim must pull a specific malicious repo and then call save_pretrained() on it), which lowers wormability and mass-exploitation likelihood — consistent with the low EPSS score and TRACK SSVC decision. However, impact is high once triggered: arbitrary file write with attacker-controlled content is a well-known primitive for achieving code execution or persistence, and the vulnerability sits in a widely-deployed, foundational ML library (transformers) used across training, fine-tuning, and inference pipelines. No active exploitation, KEV listing, or public PoC exists today, but the low bar to weaponize (publish a Hub repo, wait for adoption) means this should be tracked and patched on a normal cadence rather than treated as urgent.

How does the attack unfold?

Stage malicious repo
Attacker publishes a Hugging Face Hub repository with a crafted tokenizer_config.json whose chat_template keys contain path-traversal sequences.
AML.T0058
Victim loads and saves artifact
A developer or pipeline loads the tokenizer/processor via from_pretrained() and calls save_pretrained(), invoking the vulnerable filename-handling code.
AML.T0011.000
Path traversal write
save_pretrained() writes attacker-controlled content to a file path outside the intended save directory due to unvalidated chat_template dictionary keys.
Persistence / compromise
The arbitrary file write is used to plant persistence or achieve code execution, e.g. overwriting SSH authorized_keys, cron jobs, or shell profiles on the victim's host.
AML.T0112.001

What systems are affected?

Package Ecosystem Vulnerable Range Patched
Transformers pip < 5.10.0 5.10.0
166.7K OpenSSF 6.5 9.5K dependents Pushed 5d ago 43% patched ~88d to patch Full package profile →

Do you use Transformers? You're affected.

How severe is it?

CVSS 3.1
7.1 / 10
EPSS
0.5%
chance of exploitation in 30 days
Higher than 38% of all CVEs
Exploitation Status
No known exploitation
Sophistication
Moderate

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR None
UI Required
S Unchanged
C None
I High
A Low

What should I do?

1 step
  1. Upgrade transformers to a version that includes the upstream fix (commit eaaaf8494dd5386634ae37d1d122212fdc315be5); track the huggingface/transformers release notes to confirm which tagged release incorporates it, since affected versions listed are pre-release (<=5.8.0.dev0). Until patched: only load tokenizers/processors from verified, trusted Hub organizations; inspect tokenizer_config.json and any chat_template dictionary keys for path-traversal sequences (../, absolute paths) before trusting a third-party repo; run save_pretrained() calls with least-privilege filesystem permissions and inside sandboxed/ephemeral environments (containers with restricted mount scope) for any pipeline that ingests external Hub content; add a pre-load validation step in CI/model-ingestion pipelines that rejects configs with anomalous filename characters in template keys. Detection: monitor for unexpected file writes outside designated model-cache directories during model/tokenizer load-and-save operations.

What does CISA's SSVC say?

Decision Track
Exploitation none
Automatable No
Technical Impact partial

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

EU AI Act
Article 15 - Accuracy, robustness and cybersecurity
ISO 42001
A.6.2.6 - Third-party and supplier relationships in the AI system lifecycle
NIST AI RMF
MANAGE-4.1 - Risk treatment for third-party AI resources
OWASP LLM Top 10
LLM03 - Supply Chain Vulnerabilities

Frequently Asked Questions

What is CVE-2026-9856?

A path traversal flaw in Hugging Face `transformers` lets an attacker who publishes a malicious Hub repository control filenames written to disk when a victim saves a downloaded tokenizer or processor — `save_pretrained()` uses attacker-supplied `chat_template` dictionary keys directly as filenames, so a crafted key like `../../` sequences can escape the intended save directory and write attacker-controlled content anywhere the calling process has permissions. This is a supply-chain vector, not a remote network exploit: it triggers only when a developer or pipeline pulls a poisoned tokenizer/processor config from the Hub (including popular multimodal families — Idefics, Florence, Gemma, Phi, Qwen-VL) and calls `save_pretrained()`, but the payoff (arbitrary file write) is a classic primitive for turning into code execution — overwriting SSH `authorized_keys`, cron entries, or shell profiles. There's no CISA KEV listing, no public exploit or Nuclei template, and EPSS sits at 0.3% (78th percentile, low near-term exploitation likelihood), and CISA SSVC rates it TRACK — so this is not an emergency, but transformers underpins most self-hosted LLM/VLM pipelines, making the blast radius large if a malicious repo is adopted before detection. Action: upgrade `transformers` past the version incorporating fix commit `eaaaf8494dd5386634ae37d1d122212fdc315be5`, and until patched, treat any Hub repo not from a verified/trusted org as untrusted input — review `tokenizer_config.json`/`chat_template` contents before calling `save_pretrained()`, and run model-loading code with least-privilege filesystem access.

Is CVE-2026-9856 actively exploited?

No confirmed active exploitation of CVE-2026-9856 has been reported, but organizations should still patch proactively.

How to fix CVE-2026-9856?

Upgrade `transformers` to a version that includes the upstream fix (commit `eaaaf8494dd5386634ae37d1d122212fdc315be5`); track the huggingface/transformers release notes to confirm which tagged release incorporates it, since affected versions listed are pre-release (<=5.8.0.dev0). Until patched: only load tokenizers/processors from verified, trusted Hub organizations; inspect `tokenizer_config.json` and any `chat_template` dictionary keys for path-traversal sequences (`../`, absolute paths) before trusting a third-party repo; run `save_pretrained()` calls with least-privilege filesystem permissions and inside sandboxed/ephemeral environments (containers with restricted mount scope) for any pipeline that ingests external Hub content; add a pre-load validation step in CI/model-ingestion pipelines that rejects configs with anomalous filename characters in template keys. Detection: monitor for unexpected file writes outside designated model-cache directories during model/tokenizer load-and-save operations.

What systems are affected by CVE-2026-9856?

This vulnerability affects the following AI/ML architecture patterns: model serving, training pipelines, multimodal (VLM) inference pipelines.

What is the CVSS score for CVE-2026-9856?

CVE-2026-9856 has a CVSS v3.1 base score of 7.1 (HIGH). The EPSS exploitation probability is 0.46%.

What is the AI security impact?

Affected AI Architectures

model servingtraining pipelinesmultimodal (VLM) inference pipelines

MITRE ATLAS Techniques

AML.T0010 AI Supply Chain Compromise
AML.T0010.003 Model
AML.T0011.000 Unsafe AI Artifacts
AML.T0058 Publish Poisoned Models
AML.T0112.001 AI Artifacts

Compliance Controls Affected

EU AI Act: Article 15
ISO 42001: A.6.2.6
NIST AI RMF: MANAGE-4.1
OWASP LLM Top 10: LLM03

What are the technical details?

Original Advisory

A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` dictionary are used directly as filenames without proper validation. An attacker can exploit this by publishing a malicious Hugging Face Hub repository with a crafted `tokenizer_config.json` file. When a victim downloads and saves the tokenizer or processor, the attacker-controlled keys can escape the intended save directory, enabling arbitrary file writes with attacker-controlled content. This vulnerability affects multiple processors inheriting from `ProcessorMixin`, including Idefics, Florence, Gemma, Phi, and Qwen-VL.

Exploitation Scenario

An attacker creates and publishes a Hugging Face Hub repository impersonating a useful or trending model (e.g., a fine-tuned VLM), embedding a crafted `tokenizer_config.json` whose `chat_template` dictionary contains a key like `../../../../home/user/.ssh/authorized_keys` mapped to attacker-controlled content. A victim developer or automated pipeline discovers the repo, loads it via `AutoProcessor.from_pretrained()` or `AutoTokenizer.from_pretrained()`, and later calls `save_pretrained()` to cache or re-package it locally — a routine step in most ML workflows. The vulnerable code writes the attacker's content to the traversed path instead of the intended tokenizer directory, silently planting an SSH key, cron job, or shell profile modification that grants the attacker persistent access or code execution on the victim's host or build infrastructure.

Weaknesses (CWE)

CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'): The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

  • [Implementation] Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, "boat" may be syntactically valid because it only contains alphanumeric characters, but it is not valid if the input is only expected to contain colors such as "red" or "blue." Do not rely exclusively on looking for malicious or malformed inputs. This is likely to miss at least one undesirable input, especially if the code's environment changes. This can give attackers enough room to bypass the intended validation. However, denylis
  • [Architecture and Design] For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server.

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L

Timeline

Published
August 2, 2026
Last Modified
September 1, 2026
First Seen
August 2, 2026

Related Vulnerabilities