{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/axolotl/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:axolotl:axolotl:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-86169"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Axolotl (\u003c= 0.18.0)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","machine-learning","supply-chain"],"_cs_type":"advisory","_cs_vendors":["Axolotl"],"content_html":"\u003cp\u003eAxolotl versions through 0.18.0 are vulnerable to remote code execution (CVE-2026-86169) due to an insecure default configuration within the multipack patch path. The application fails to properly restrict the trust_remote_code parameter, which defaults to None rather than the intended False. This oversight enables a security guard bypass, allowing the application to load code from untrusted sources. An attacker can leverage this flaw by providing a crafted Hugging Face model repository as the base_model. When Axolotl executes the AutoModelForCausalLM.from_pretrained function, the malicious model is loaded with hardcoded trust_remote_code=True, resulting in the execution of arbitrary Python code within the host environment. This vulnerability is significant for organizations using Axolotl for fine-tuning Large Language Models, as it allows for full compromise of the training infrastructure.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker creates a malicious Hugging Face model repository containing arbitrary Python code.\u003c/li\u003e\n\u003cli\u003eAttacker configures the target Axolotl instance to use the malicious model as the base_model.\u003c/li\u003e\n\u003cli\u003eAxolotl triggers the multipack patch path during the training process initialization.\u003c/li\u003e\n\u003cli\u003eThe application logic fails to override trust_remote_code=None, defaulting to an insecure state.\u003c/li\u003e\n\u003cli\u003eAxolotl calls AutoModelForCausalLM.from_pretrained to load the specified base_model.\u003c/li\u003e\n\u003cli\u003eThe underlying Hugging Face transformer library executes the embedded Python code from the repository.\u003c/li\u003e\n\u003cli\u003eAttacker achieves remote code execution within the context of the user or service account running the Axolotl training job.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution on the system running Axolotl. This can lead to total system compromise, exfiltration of sensitive model training data, theft of API tokens, or further lateral movement within the network. Sectors utilizing automated AI/ML pipelines and fine-tuning frameworks are primary targets.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate Axolotl to a version beyond 0.18.0 that properly enforces trust_remote_code=False. In the interim, implement strict egress filtering on training nodes to prevent model-loading infrastructure from reaching unauthorized or untrusted repositories. Audit all model configuration files for the use of external repositories.\u003c/p\u003e\n\u003ch2 id=\"impact-1\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eImpact includes unauthorized code execution on the training server.\u003c/p\u003e\n","date_modified":"2026-09-05T11:31:53Z","date_published":"2026-09-05T11:31:53Z","id":"https://feed.craftedsignal.io/briefs/2026-09-axolotl-rce/","summary":"Axolotl versions through 0.18.0 contain a remote code execution vulnerability where an insecure default configuration allows attackers to bypass security guards and execute arbitrary Python code.","title":"Remote Code Execution in Axolotl via trust_remote_code Bypass","url":"https://feed.craftedsignal.io/briefs/2026-09-axolotl-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Axolotl","version":"https://jsonfeed.org/version/1.1"}