THREAT OPS › Threat News › [NVD] CVE-2026-9856 (HIGH 7.1) — A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` di
[NVD] CVE-2026-9856 (HIGH 7.1) — A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` di
CVE-2026-9856 CVSS: 7.1 HIGH Published: 2026-08-02T16:16:25.413
A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` dictionary are used directly as filenames without proper
Indicators of compromise
- CVE-2026-9856cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-9856