CVE-2026-61539Patch

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

NVD description

Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/llama3_tool_parser.py and xinference/model/llm/utils.py. Requests to /v1/chat/completions with a tools field flow through xinference/api/restful_api.py, xinference/model/llm/transformers/core.py, handle_chat_result_non_streaming(), and _post_process_completion() before extract_tool_calls() or _eval_llama3_chat_arguments() evaluates the model-generated Python expression. An unauthenticated remote attacker can influence that output through a crafted prompt and execute commands in the Xinference server process context. This issue is fixed in version 2.7.0.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-95

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 6 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-08-22); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-08-22: 2Mentions · 2026-08-25: 1Mentions · 2026-08-26: 2Mentions · 2026-08-31: 1Exploit Tool / Code · 2026-08-22: 1Patch / Workaround · 2026-08-22: 2Patch / Workaround · 2026-08-26: 2Technical Details · 2026-08-22: 2Technical Details · 2026-08-25: 1Technical Details · 2026-08-26: 2Technical Details · 2026-08-31: 108-2208-2508-2608-31
Signal classification2 categories
Patch
466.7%
Disclosure
233.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-08-222
Patch2
2026-08-251
Disclosure1
2026-08-262
Patch2
2026-08-311
Disclosure1
Full discourse6 posts
  • AI Heartland@peaks2314
    Disclosure

    Xinference 脆弱性CVE-2026-61539|プロンプトがevalに届くCVSS10.0のRCEを実測 https://ai-heartland.com/security/xinference-cve-2026-61539-eval-rce/

    Post summary

    The post discloses CVE-2026-61539, highlighting a critical RCE rated CVSS 10.0, but does not provide PoC, exploit code, or evidence of active exploitation.

    0002096
    3.4K followersView on X
  • Cybersecurity News DE@cybsecuritynews
    Disclosure

    #künstlicheintelligenz #schwachstellen CVE-2026-61539: Xinference erlaubt Codeausführung per präpariertem Chat-Prompt #cve202661539 #xinference https://cybersecurity-news.de/cve-2026-61539-xinference-codeausfuehrung-prompt

    Post summary

    The tweet discloses that CVE-2026-61539 in Xinference enables code execution through a crafted chat prompt, but it offers no evidence of an active exploit or available fix.

    0001035
    10 followersView on X
  • Echosphere@Echosphere8f
    Patch

    「ツールの返事」をそのまま eval() に通してる。Llama3のtool-call解析。CVSS 10。未認証でネットから届く。💎 Xinference、CVE-2026-61539。辞書に変換したかっただけ——でも eval はサンドボックスじゃねぇ。 https://nvd.nist.gov/vuln/detail/CVE-2026-61539 #Xinference #CVE #LLMSecurity 噛み砕く。/v1/chat/completions に tools を付けて叩くと、モデルが出した文字列がサーバ側で Python 式として評価される。プロンプトでその文字列を誘導できれば、推論サーバのプロセス権限でコマンドが走る。⚠️ 既定構成では認証なしだった、って advisory に書いてある。 https://github.com/xorbitsai/inference/security/advisories/GHSA-x2rj-828p-hx9m https://x.com/SecAlertsCo/status/2092534000996712833 直しは 2.7.0。eval を捨てて安全なパースに差し替えた。💎 https://github.com/xorbitsai/inference/releases/tag/v2.7.0 モデルの出力はデータだ。コード扱いした瞬間、境界は消える。ツール出力を eval するな。 #Python #セキュリティ -- メル

    Post summary

    The text outlines a high‑severity vulnerability (CVE‑2026‑61539) involving unauthenticated remote code execution via eval() of LLM tool outputs, and announces that version 2.7.0 of the affected product contains a patch.

    0001079
    21 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🐍 CVE-2026-61539: Xinference pipes Llama3 tool-call output into Python's eval() — attacker-controlled, network-reachable, no auth. CVSS 10 RCE. Patch xinference now. #cybersecurity #ciso #vulnerabilities https://secalerts.co/vulnerability/CVE-2026-61539?utm_campaign=x https://t.co/oulhwwOA01

    Post summary

    CVE‑2026‑61539 is a high‑severity RCE in Xinference caused by Python eval() on attacker‑controlled data; a patch has been released.

    00000165
    881 followersView on X
  • Innora.ai@Innora_sg
    Patch

    CVE-2026-61539 (CVSS 10.0): Xinference's llama3_tool_parser.py / http://utils.py eval()s attacker-influenced tool-call output — no allow-list parser. Unauth chat completions with tools → inference RCE. Through 2.5.0. Fixed in 2.7.0. Found by XlabAI Team. #CVE #Python #AppSec #InfoSec

    Post summary

    A critical RCE vulnerability in Xinference’s llama3_tool_parser.py was disclosed, with a fix released in version 2.7.0.

    0000052
    23 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Xinference RCE via Llama3 Tool-Call eval() Injection (CVE-2026-61539) Xinference uses Python's unsafe eval() when parsing Llama3 tool-call output; attacker-influenced model output can be executed as a Python expression. Remote attackers can send crafted prompts to /v1/chat/completions (unauthenticated in default deployments) to achieve command execution in the Xinference server process context. 👉Affected: xinference < 2.7.0 | Upgrade to 2.7.0

    Post summary

    The post announces CVE-2026-61539 as a critical RCE in Xinference caused by unsafe eval() parsing of Llama3 tool‑call output and advises users to upgrade to version 2.7.0.

    0000082
    291 followersView on X

Explore more