CVE-2026-85668 | Xorbitsai Xinference up to 3.3.0 Auto Register config.json model_path path traversal (4a94832)
A vulnerability described as problematic has been identified in Xorbitsai Xinference up to 3.3.0. This vulnerability affects unknown code of the file config.json of the component Auto Register. Executing a manipulation of the argument model_path can lead to path traversal.
This vulnerability is registered as CVE-2026-85668. It is possible to launch the attack remotely. No exploit is available.
It is best practice to apply a patch to resolve this issue.VulDB Recent EntriesRead More