Skip to content
Threat Feed
high advisory

Remote Code Execution in Xinference via Unsafe Model Loading

Xinference versions prior to 2.12.0 are vulnerable to remote code execution because they unconditionally enable 'trust_remote_code=True' when loading models, allowing attackers to execute arbitrary Python code via crafted model configurations.

CVE search metadata

CVE search record: CVE-2026-76841. Severity: high. CVSS: 8.8. KEV: no. Product: Xinference (< 2.12.0). Brief: Remote Code Execution in Xinference via Unsafe Model Loading. Brief link: https://feed.craftedsignal.io/briefs/2026-08-xinference-rce/

Xinference versions prior to 2.12.0 contain a critical remote code execution (RCE) vulnerability (CVE-2026-76841) rooted in the insecure implementation of Hugging Face Transformers model loading. The application contains six distinct loader call sites that pass 'trust_remote_code=True' to the underlying Transformers library, either as a hardcoded literal or a default configuration.

This implementation allows an attacker with model launch access to register a custom model type and supply a malicious model path. During the model loading sequence, the server invokes 'AutoTokenizer.from_pretrained'. If an attacker provides a 'tokenizer_config.json' file containing an 'auto_map' entry, the server will automatically import and execute arbitrary Python code defined within the model directory. This code executes with the full privileges of the Xinference worker process. Version 2.12.0 mitigates this issue by introducing the 'XINFERENCE_TRUST_REMOTE_CODE' setting and requiring explicit enablement to permit remote code execution for non-bundled models.

Impact

An attacker exploiting this vulnerability achieves remote code execution in the context of the worker process. This can lead to full compromise of the hosting server, sensitive data exfiltration, or lateral movement within the environment. This vulnerability affects any deployment of Xinference prior to version 2.12.0 that allows untrusted users to launch or register new model paths.

Recommendation

  • Immediately upgrade all instances of Xinference to version 2.12.0 or later to ensure the 'trust_remote_code' functionality is gated by configuration.
  • Audit current model registration logs for the registration of arbitrary model paths or custom model types by unauthorized users.
  • Restrict model registration and launch capabilities to trusted administrators or authenticated service identities within the infrastructure.

Immediate actions

Upgrade Xinference to version 2.12.0 or later

IT Operations 48h

Mitigations

Restrict access to the model registration API

immediate IT Operations

CVE-2026-76841