{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/xinference-3.x-commit-4a94832/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:xorbits:xinference:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-85668"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Xinference (3.x, commit 4a94832)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","file-read","webserver"],"_cs_type":"advisory","_cs_vendors":["Xorbits"],"content_html":"\u003cp\u003eXinference, an open-source model serving framework, is affected by a critical arbitrary file read vulnerability (CVE-2026-85668) within its model registration mechanism. The vulnerability exists in the POST /v1/models/llm/auto-register endpoint, which fails to enforce authentication or restrict file paths provided in the model_path parameter. When a user provides a path, the application attempts to locate and parse config.json, tokenizer_config.json, and chat_template.jinja files within that directory. Because these contents are reflected back in the API response, an unauthenticated attacker can supply arbitrary filesystem paths to read sensitive configuration files or other data stored in locations where these specific filenames exist. This issue affects Xinference version 3.x and commit 4a94832. Successful exploitation allows unauthorized information disclosure, potentially exposing system credentials, environment variables, or other sensitive configuration parameters to remote attackers.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a high risk to deployments of Xinference, as it permits unauthenticated remote attackers to enumerate files and exfiltrate content from the host server. Depending on the environment, this could lead to the exposure of API keys, database credentials, or internal service configurations, facilitating further compromise of the infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Xinference to a version that implements proper input validation and path sanitization for the model registration process.\u003c/li\u003e\n\u003cli\u003eImplement network-level access controls to ensure the Xinference API endpoint is not exposed to the public internet.\u003c/li\u003e\n\u003cli\u003eAudit logs for the POST /v1/models/llm/auto-register endpoint to detect anomalous model_path inputs containing path traversal sequences (e.g., ../).\u003c/li\u003e\n\u003cli\u003eConfigure the Xinference service to run with the least privilege necessary, limiting the filesystem paths the application process can access.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T15:29:05Z","date_published":"2026-09-04T15:29:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-xinference-file-read/","summary":"Xinference versions 3.x and commit 4a94832 contain an unauthenticated arbitrary file read vulnerability via the model_path parameter in the auto-register endpoint.","title":"Unauthenticated Arbitrary File Read in Xinference","url":"https://feed.craftedsignal.io/briefs/2026-09-xinference-file-read/"}],"language":"en","title":"CraftedSignal Threat Feed - Xinference (3.x, Commit 4a94832)","version":"https://jsonfeed.org/version/1.1"}