Vendor
Xinference versions 3.x and commit 4a94832 contain an unauthenticated arbitrary file read vulnerability via the model_path parameter in the auto-register endpoint.