ThreatCluster

Remote Code Execution Vulnerability in Axolotl Affects Multiple Users

First seen 6 Sep 2026, 14:12 UTC CveOsv.Dev 46

Article Content

Browse articles
ThreatCluster

A remote code execution vulnerability identified as CVE-2026-86169 affects Axolotl versions up to 0.18.0. The flaw arises from the multipack patch path where the trust_remote_code setting defaults to None instead of False, allowing attackers to bypass security measures. By crafting a malicious Hugging Face model repository, attackers can execute arbitrary Python code during the loading process. This vulnerability has a CVSS score of 8.7, indicating a high severity level. Users of Axolotl are urged to apply patches immediately to mitigate risks. The vulnerability was published on September 5, 2026, and is currently not known to be actively exploited. The issue has been addressed in a patch available on GitHub.

Key Points: • CVE-2026-86169 allows remote code execution in Axolotl versions up to 0.18.0. • Attackers can exploit the flaw by using malicious Hugging Face model repositories. • A patch is available, and users should update their systems immediately.

Ask AI about this cluster

Timeline

2026-09-05
CVE-2026-86169 published
The vulnerability affecting Axolotl was officially published, detailing the remote code execution risk.
Cve
2026-09-06
Vulnerability details reported
The vulnerability was reported with a CVSS score of 8.7, indicating high severity.
Osv.Dev