CVE-2026-76841 | xorbitsai inference up to 2.11.x Model Loader core.py AutoTokenizer.from_pretrained trust_remote_code code injection
A vulnerability, which was classified as critical, has been found in xorbitsai inference up to 2.11.x. This vulnerability affects the function AutoTokenizer.from_pretrained of the file xinference/model/rerank/core.py of the component Model Loader. The manipulation of the argument trust_remote_code leads to code injection.
This vulnerability is documented as CVE-2026-76841. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More