CRITICAL
Xorbits AI
CVE published 2026-08-21
CVE-2026-61539
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T21:17:00.867Z and has not been modified since then. The CVE-2026-61539 vulnerability in Xinference, an inference API for running open-source models, allows unauthenticated remote attackers to execute commands in the server process context. This issue arises from the API's handling of Llama3 tool- [truncated]