Vulnerability Description
Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. Six loader call sites pass trust_remote_code=True as a literal or as an unconditional default: RerankModel._get_tokenizer in xinference/model/rerank/core.py, SentenceTransformerRerankModel.load in xinference/model/rerank/sentence_transformers/core.py, SentenceTransformerEmbeddingModel.load in xinference/model/embedding/sentence_transformers/core.py, FlagEmbeddingModel.load in xinference/model/embedding/flag/core.py, and two sites in xinference/model/llm/transformers/core.py where PytorchModel._sanitize_model_config and PytorchModel._get_components default the value to True. Because a caller with model launch access can register a model whose type is unknown and supply an arbitrary model path, the server reaches _auto_detect_type and then AutoTokenizer.from_pretrained, which imports and executes Python declared by the model directory's own tokenizer_config.json auto_map, running attacker-supplied code with the privileges of the worker process. Version 2.12.0 gates every site behind allow_trust_remote_code and the XINFERENCE_TRUST_REMOTE_CODE setting, permitting remote code only for bundled built-in models.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/xorbitsai/inference
- https://github.com/xorbitsai/inference/blob/v2.11.0/xinference/model/rerank/core
- https://github.com/xorbitsai/inference/issues/5023
- https://github.com/xorbitsai/inference/pull/5027
- https://www.vulncheck.com/advisories/xinference-through-remote-code-execution-vi
FAQ
What is CVE-2026-76841?
CVE-2026-76841 is a vulnerability with a CVSS score of 8.8 (HIGH). Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. Six loader call sites pass trust_remote_code=True a...
How severe is CVE-2026-76841?
CVE-2026-76841 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-76841?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.