xinference
Swap GPT for any LLM by changing a single line of code. Xinference lets you run open-source, speech, and multimodal models on cloud, on-prem, or your laptop — all through one unified, production-ready inference API.
Activity
- Latest release
- 4d ago
- Total releases
- 151
- Cadence
- ~13 days
- Last 12 months
- 28
Reach
- Stars
- 9.6k
Details
- License
- Apache-2.0
- First release
- Jul 07, 2023
| Version | Released | |
|---|---|---|
3.4.0
minor
| ||
3.3.0
minor
| ||
3.2.1
patch
| ||
3.2.0
minor
| ||
3.1.0
minor
| ||
3.1.0rc1
pre
| ||
3.0.0
major
| ||
2.12.0
minor
| ||
2.11.0
minor
| ||
2.10.0
minor
| ||
2.9.0
minor
| ||
2.8.0
minor
| ||
2.7.0
minor
| ||
2.5.0
minor
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.4.0
minor
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.3.0
minor
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.0
minor
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.17.1
patch
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.17.0
minor
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.16.0
minor
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.15.0
minor
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.14.0
minor
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.13.0
minor
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.12.0
minor
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.11.0.post1
pre
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.11.0
minor
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.10.1
patch
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.10.0
minor
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.9.1
patch
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.9.0
minor
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.8.1
patch
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.8.1rc1
pre
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.8.0
minor
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.7.1.post1
pre
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.7.1
patch
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.7.0.post1
pre
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.7.0
minor
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.6.1
patch
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.6.0.post1
pre
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.6.0
minor
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.1
patch
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.0.post2
pre
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.0.post1
pre
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.0
minor
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.1
patch
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.0
minor
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.3.1.post1
pre
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.3.1
patch
1 CVE
CVE-2026-61539
PYSEC-2026-3946
GHSA-x2rj-828p-hx9m
Sep 10, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryXinference used Python's unsafe DetailsUsers can interact with deployed models through Xinference's OpenAI-compatible When the Transformers backend is used, inference results flow through the batching logic in The Llama3 tool-call parser is implemented in
The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However,
When the expression reaches ScoreSeverity: Critical CVSS v3.1: 10.0 Vector: Rationale:
CreditThis vulnerability was discovered by:
Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
+ 126 more Show less
0.10.1
0.10.2
0.10.2.post1
0.10.3
0.11.0
0.11.1
0.11.2
0.11.2.post1
0.11.3
0.12.0
0.12.1
0.12.2
0.12.2.post1
0.12.3
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.0.post1
0.14.1
0.14.1.post1
0.14.2
0.14.3
0.14.4
0.14.4.post1
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.16.0
0.16.1
0.16.2
0.16.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.7.2
0.7.3
0.7.3.1
0.7.4
0.7.4.1
0.7.5
0.8.0
0.8.1
0.8.2
0.8.3
0.8.3.1
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.0.post1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.0.post1
1.3.0.post2
1.3.1
1.3.1.post1
1.4.0
1.4.1
1.5.0
1.5.0.post1
1.5.0.post2
1.5.1
1.6.0
1.6.0.post1
1.6.1
1.7.0
1.7.0.post1
1.7.1
1.7.1.post1
1.8.0
1.8.1
1.8.1rc1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
Fixed in
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev |