CVE-2026-61539 | XorbitsAI Xinference up to 2.6.x Llama3 Tool Parser llama3_tool_parser.py extract_tool_calls Tools code injection
A vulnerability was found in XorbitsAI Xinference up to 2.6.x. It has been rated as critical. This issue affects the function extract_tool_calls of the file xinference/model/llm/tool_parsers/llama3_tool_parser.py of the component Llama3 Tool Parser. Performing a manipulation of the argument Tools results in code injection.
This vulnerability was named CVE-2026-61539. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.VulDB Recent EntriesRead More