AI Heartland[verified]@peaks2314Disclosure
The post discloses CVE-2026-61539, highlighting a critical RCE rated CVSS 10.0, but does not provide PoC, exploit code, or evidence of active exploitation.
Echosphere[verified]@Echosphere8fPatch
The text outlines a high‑severity vulnerability (CVE‑2026‑61539) involving unauthenticated remote code execution via eval() of LLM tool outputs, and announces that version 2.7.0 of the affected product contains a patch.
Innora.ai[verified]@Innora_sgPatch
A critical RCE vulnerability in Xinference’s llama3_tool_parser.py was disclosed, with a fix released in version 2.7.0.
Upwind Security MDR[verified]@UpwindMDRPatch
The post announces CVE-2026-61539 as a critical RCE in Xinference caused by unsafe eval() parsing of Llama3 tool‑call output and advises users to upgrade to version 2.7.0.
Cybersecurity News DE@cybsecuritynewsDisclosure
The tweet discloses that CVE-2026-61539 in Xinference enables code execution through a crafted chat prompt, but it offers no evidence of an active exploit or available fix.
SecAlerts@SecAlertsCoPatch
CVE‑2026‑61539 is a high‑severity RCE in Xinference caused by Python eval() on attacker‑controlled data; a patch has been released.