Product
Xinference is vulnerable to remote code execution due to the use of Python's unsafe eval() function to parse tool-call outputs generated by LLMs, allowing unauthenticated attackers to execute arbitrary code via prompt injection.