{"id":"PYSEC-2026-3929","summary":"Transformers save_pretrained path traversal allows arbitrary file writes through chat template names","details":"A vulnerability in huggingface/transformers versions \u003c 5.10.0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` dictionary are used directly as filenames without proper validation. An attacker can exploit this by publishing a malicious Hugging Face Hub repository with a crafted `tokenizer_config.json` file. When a victim downloads and saves the tokenizer or processor, the attacker-controlled keys can escape the intended save directory, enabling arbitrary file writes with attacker-controlled content. This vulnerability affects multiple processors inheriting from `ProcessorMixin`, including Idefics, Florence, Gemma, Phi, and Qwen-VL.","aliases":["CVE-2026-9856","GHSA-xrqw-3rrv-vx5w"],"modified":"2026-09-10T12:15:13.263552340Z","published":"2026-09-10T09:44:51.053247Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9856"},{"type":"WEB","url":"https://github.com/huggingface/transformers/pull/46191"},{"type":"WEB","url":"https://github.com/huggingface/transformers/commit/eaaaf8494dd5386634ae37d1d122212fdc315be5"},{"type":"PACKAGE","url":"https://github.com/huggingface/transformers"},{"type":"WEB","url":"https://huntr.com/bounties/362824d5-fe18-40e8-a6cf-62277f97a170"},{"type":"PACKAGE","url":"https://pypi.org/project/transformers"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-xrqw-3rrv-vx5w"}],"affected":[{"package":{"name":"transformers","ecosystem":"PyPI","purl":"pkg:pypi/transformers"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.0"}]}],"versions":["0.1","2.0.0","2.1.0","2.1.1","2.10.0","2.11.0","2.2.0","2.2.1","2.2.2","2.3.0","2.4.0","2.4.1","2.5.0","2.5.1","2.6.0","2.7.0","2.8.0","2.9.0","2.9.1","3.0.0","3.0.1","3.0.2","3.1.0","3.2.0","3.3.0","3.3.1","3.4.0","3.5.0","3.5.1","4.0.0","4.0.0rc1","4.0.1","4.1.0","4.1.1","4.10.0","4.10.1","4.10.2","4.10.3","4.11.0","4.11.1","4.11.2","4.11.3","4.12.0","4.12.1","4.12.2","4.12.3","4.12.4","4.12.5","4.13.0","4.14.0","4.14.1","4.15.0","4.16.0","4.16.1","4.16.2","4.17.0","4.18.0","4.19.0","4.19.1","4.19.2","4.19.3","4.19.4","4.2.0","4.2.1","4.2.2","4.20.0","4.20.1","4.21.0","4.21.1","4.21.2","4.21.3","4.22.0","4.22.1","4.22.2","4.23.0","4.23.1","4.24.0","4.25.0","4.25.1","4.26.0","4.26.1","4.27.0","4.27.1","4.27.2","4.27.3","4.27.4","4.28.0","4.28.1","4.29.0","4.29.1","4.29.2","4.3.0","4.3.0rc1","4.3.1","4.3.2","4.3.3","4.30.0","4.30.1","4.30.2","4.31.0","4.32.0","4.32.1","4.33.0","4.33.1","4.33.2","4.33.3","4.34.0","4.34.1","4.35.0","4.35.1","4.35.2","4.36.0","4.36.1","4.36.2","4.37.0","4.37.1","4.37.2","4.38.0","4.38.1","4.38.2","4.39.0","4.39.1","4.39.2","4.39.3","4.4.0","4.4.1","4.4.2","4.40.0","4.40.1","4.40.2","4.41.0","4.41.1","4.41.2","4.42.0","4.42.1","4.42.2","4.42.3","4.42.4","4.43.0","4.43.1","4.43.2","4.43.3","4.43.4","4.44.0","4.44.1","4.44.2","4.45.0","4.45.1","4.45.2","4.46.0","4.46.1","4.46.2","4.46.3","4.47.0","4.47.1","4.48.0","4.48.1","4.48.2","4.48.3","4.49.0","4.5.0","4.5.1","4.50.0","4.50.1","4.50.2","4.50.3","4.51.0","4.51.1","4.51.2","4.51.3","4.52.0","4.52.1","4.52.2","4.52.3","4.52.4","4.53.0","4.53.1","4.53.2","4.53.3","4.54.0","4.54.1","4.55.0","4.55.1","4.55.2","4.55.3","4.55.4","4.56.0","4.56.1","4.56.2","4.57.0","4.57.1","4.57.2","4.57.3","4.57.4","4.57.5","4.57.6","4.6.0","4.6.1","4.7.0","4.8.0","4.8.1","4.8.2","4.9.0","4.9.1","4.9.2","5.0.0","5.0.0rc0","5.0.0rc1","5.0.0rc2","5.0.0rc3","5.1.0","5.2.0","5.3.0","5.4.0","5.5.0","5.5.1","5.5.2","5.5.3","5.5.4","5.6.0","5.6.1","5.6.2","5.7.0","5.8.0","5.8.1","5.9.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/transformers/PYSEC-2026-3929.yaml"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L"}]}