PatchSiren

xorbitsai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH xorbitsai CVE published 2026-08-24

CVE-2026-76841

CVE-2026-76841 Xinference Remote Code Execution Vulnerability. The Xinference library loads models with Hugging Face remote code execution unconditionally enabled, allowing a caller with model launch access to register a model with an arbitrary model path, leading to the execution of attacker-supplied code with the privileges of the worker process. Defenders responsible for Xinference deployments should a [truncated]