
🚨 CRITICAL - LLaMA-Factory WebUI remote code execution via untrusted model loading (CVE-2026-58116) LLaMA-Factory through 0.9.5 is vulnerable to remote code execution in its WebUI Chat and Training flows when loading models via Hugging Face transformers AutoTokenizer.from_pretrained() and AutoModel.from_pretrained(). The root cause is improper input validation combined with unsafe dynamic code loading (trust_remote_code=True), enabling execution of repository-provided Python code. An attacker with WebUI access can supply a malicious local/remote model path that points to a crafted model repo, causing the server to fetch and run attacker-controlled code during model initialization. Successful exploitation yields arbitrary code execution with the LLaMA-Factory server process privileges, enabling full host compromise, data theft, and lateral movement. 👉 Affected: LLaMA-Factory <= 0.9.5 | Upgrade to No fix yet - treat as suspicious
Post summary
The post announces CVE-2026-58116 as a critical remote code execution flaw in LLaMA-Factory WebUI via untrusted model loading, providing technical details but no PoC, exploit code, or patch.
