CVE-2026-58116Disclosure(hiyouga / llama-factory)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to execute arbitrary Python code by supplying a malicious model path in the Chat or Training interfaces. The application passes user-supplied model path input unvalidated into AutoTokenizer.from_pretrained() and AutoModel.from_pretrained() with a hardcoded trust_remote_code=True parameter, causing the Hugging Face transformers library to fetch and execute arbitrary code from a remote or local model repository with the privileges of the server process.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-829

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • llama-factory

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
llama-factory

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-30: 1Technical Details · 2026-06-30: 106-30
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - LLaMA-Factory WebUI remote code execution via untrusted model loading (CVE-2026-58116) LLaMA-Factory through 0.9.5 is vulnerable to remote code execution in its WebUI Chat and Training flows when loading models via Hugging Face transformers AutoTokenizer.from_pretrained() and AutoModel.from_pretrained(). The root cause is improper input validation combined with unsafe dynamic code loading (trust_remote_code=True), enabling execution of repository-provided Python code. An attacker with WebUI access can supply a malicious local/remote model path that points to a crafted model repo, causing the server to fetch and run attacker-controlled code during model initialization. Successful exploitation yields arbitrary code execution with the LLaMA-Factory server process privileges, enabling full host compromise, data theft, and lateral movement. 👉 Affected: LLaMA-Factory <= 0.9.5 | Upgrade to No fix yet - treat as suspicious

    Post summary

    The post announces CVE-2026-58116 as a critical remote code execution flaw in LLaMA-Factory WebUI via untrusted model loading, providing technical details but no PoC, exploit code, or patch.

    0000068
    232 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphiyougallama-factory---

Explore more