{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/xinference/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-76841"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Xinference (\u003c 2.12.0)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","vulnerability","ai-security"],"_cs_type":"advisory","_cs_vendors":["Xinference"],"content_html":"\u003cp\u003eXinference versions prior to 2.12.0 contain a critical remote code execution (RCE) vulnerability (CVE-2026-76841) rooted in the insecure implementation of Hugging Face Transformers model loading. The application contains six distinct loader call sites that pass 'trust_remote_code=True' to the underlying Transformers library, either as a hardcoded literal or a default configuration.\u003c/p\u003e\n\u003cp\u003eThis implementation allows an attacker with model launch access to register a custom model type and supply a malicious model path. During the model loading sequence, the server invokes 'AutoTokenizer.from_pretrained'. If an attacker provides a 'tokenizer_config.json' file containing an 'auto_map' entry, the server will automatically import and execute arbitrary Python code defined within the model directory. This code executes with the full privileges of the Xinference worker process. Version 2.12.0 mitigates this issue by introducing the 'XINFERENCE_TRUST_REMOTE_CODE' setting and requiring explicit enablement to permit remote code execution for non-bundled models.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eAn attacker exploiting this vulnerability achieves remote code execution in the context of the worker process. This can lead to full compromise of the hosting server, sensitive data exfiltration, or lateral movement within the environment. This vulnerability affects any deployment of Xinference prior to version 2.12.0 that allows untrusted users to launch or register new model paths.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade all instances of Xinference to version 2.12.0 or later to ensure the 'trust_remote_code' functionality is gated by configuration.\u003c/li\u003e\n\u003cli\u003eAudit current model registration logs for the registration of arbitrary model paths or custom model types by unauthorized users.\u003c/li\u003e\n\u003cli\u003eRestrict model registration and launch capabilities to trusted administrators or authenticated service identities within the infrastructure.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T16:02:13Z","date_published":"2026-08-24T16:02:13Z","id":"https://feed.craftedsignal.io/briefs/2026-08-xinference-rce/","summary":"Xinference versions prior to 2.12.0 are vulnerable to remote code execution because they unconditionally enable 'trust_remote_code=True' when loading models, allowing attackers to execute arbitrary Python code via crafted model configurations.","title":"Remote Code Execution in Xinference via Unsafe Model Loading","url":"https://feed.craftedsignal.io/briefs/2026-08-xinference-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Xinference","version":"https://jsonfeed.org/version/1.1"}