cvefeed.io Critical RCE Vulnerability Discovered in LLaMA-Factory WebUI
Article Content
- •CVE-2026-58116 allows RCE via malicious model paths in LLaMA-Factory WebUI.
- •The vulnerability affects all versions up to 0.9.5 and has a CVSS score of 9.8.
- •Mitigation includes updating the software and restricting access to the WebUI.
A critical remote code execution vulnerability, CVE-2026-58116, has been identified in LLaMA-Factory versions up to 0.9.5. The flaw allows attackers to execute arbitrary Python code by supplying a malicious model path in the WebUI Chat and Training interfaces. This vulnerability is due to unvalidated user input being passed to Hugging Face model-loading functions with trust_remote_code enabled. The CVSS 3.1 score is 9.8, indicating high severity. Recommended mitigations include updating LLaMA-Factory and restricting WebUI access. Public reports confirm the issue is remotely exploitable, raising concerns about widespread impact. No configuration options exist to disable the unsafe behavior, increasing vulnerability exposure.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2026-58116 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…