HIGH
xorbitsai
CVE published 2026-08-24
CVE-2026-76841
CVE-2026-76841 Xinference Remote Code Execution Vulnerability. The Xinference library loads models with Hugging Face remote code execution unconditionally enabled, allowing a caller with model launch access to register a model with an arbitrary model path, leading to the execution of attacker-supplied code with the privileges of the worker process. Defenders responsible for Xinference deployments should a [truncated]