Last seen August 3, 2026

Florence path traversal Vulnerability

Evidence indicates that Florence is affected by a security issue. Reported affected versions include < 5.10.0.

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

Evidence indicates that Florence is affected by a security issue. Reported affected versions include < 5.10.0.

Why This Matters

Publisher reporting describes a security event affecting Phi. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.

Recommended Action

Upgrade to version 5.10.0 or later Identify deployments of Florence matching the evidenced affected versions: < 5.10.0.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Aug 03, 2026 00:00

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Affected versions: < 5.10.0

Primary entities:

huggingfaceFlorenceGemmaIdeficsPhiPreTrainedTokenizerBase

Timeline

  • Incident first seen
    Aug 03, 2026 00:00

    BugSkan first recorded this incident.

  • Transformers save_pretrained path traversal allows arbitrary file writes through chat template names
    Aug 03, 2026 00:00

    GitHub Advisory Database · Vulnerability

Sources

Transformers save_pretrained path traversal allows arbitrary file writes through chat template names

GitHub Advisory Database · Aug 03, 2026 00:00

A vulnerability in huggingface/transformers versions < 5.10.0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` dictionary are used directly as filenames without proper validation. An attacker can exploit this by publishing a malicious Hugging Face Hub repository with a crafted `tokenizer_config.json` file. When a victim downloads and saves the tokenizer or processor, the attacker-controlled keys can escape the intended save directory, enabling arbitrary file writes with attacker-controlled content. This vulnerability affects multiple processors inheriting from `ProcessorMixin`, including Idefics, Florence, Gemma, Phi, and Qwen-VL.

Open publisher source

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

← Back to incident intelligence