Florence path traversal Vulnerability
Evidence indicates that Florence is affected by a security issue. Reported affected versions include < 5.10.0.
What Happened
Evidence indicates that Florence is affected by a security issue. Reported affected versions include < 5.10.0.
Why This Matters
Publisher reporting describes a security event affecting Phi. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Upgrade to version 5.10.0 or later Identify deployments of Florence matching the evidenced affected versions: < 5.10.0.
Exposure
Exposure unknown
Aug 03, 2026 00:00
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Affected versions: < 5.10.0
Primary entities:
Timeline
-
Incident first seen
Aug 03, 2026 00:00BugSkan first recorded this incident.
-
Transformers save_pretrained path traversal allows arbitrary file writes through chat template names
Aug 03, 2026 00:00GitHub Advisory Database · Vulnerability
Sources
GitHub Advisory Database · Aug 03, 2026 00:00
A vulnerability in huggingface/transformers versions < 5.10.0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` dictionary are used directly as filenames without proper validation. An attacker can exploit this by publishing a malicious Hugging Face Hub repository with a crafted `tokenizer_config.json` file. When a victim downloads and saves the tokenizer or processor, the attacker-controlled keys can escape the intended save directory, enabling arbitrary file writes with attacker-controlled content. This vulnerability affects multiple processors inheriting from `ProcessorMixin`, including Idefics, Florence, Gemma, Phi, and Qwen-VL.
Open publisher sourceMy Interests Match
Create an account to see which incidents overlap with your interests.