THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-9856 (HIGH 7.1) — A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` di

[NVD] CVE-2026-9856 (HIGH 7.1) — A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` di

mednvdPublished 2026-08-02

CVE-2026-9856 CVSS: 7.1 HIGH Published: 2026-08-02T16:16:25.413

A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` dictionary are used directly as filenames without proper

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-9856