Junglewise Threat Intelligence

CVE-2026-85668: Xinference arbitrary file read in LLM auto-register endpoint

CVE-2026-85668 · Severity: high · CVSS 7.5 · Published 2026-09-04

Technologies: Xorbits Xinference.

Executive brief

Xinference is an inference server that allows running open-source language models through a unified API. An unauthenticated attacker can exploit a file read vulnerability in the model auto-register endpoint to read arbitrary files from the server, potentially exposing sensitive configuration data and other files stored on the same filesystem.

Technical details

The vulnerability is an unauthenticated arbitrary-path file read flaw in the POST /v1/models/llm/auto-register endpoint. The endpoint accepts a caller-supplied model_path parameter without authentication or path validation. An attacker can supply a path to any directory, and the endpoint will read and parse config.json, tokenizer_config.json, and chat_template.jinja files at that location, reflecting the parsed content back to the caller. This allows an unauthenticated attacker to probe the server filesystem and extract file contents from any directory accessible by the Xinference process.

Affected products

  • Xorbits Xinference v3.x (affected commit 4a94832)

Timeline

  • 2026-09-04: disclosed

References