LLaMA-Factory Remote Code Execution Via WebUI Model Path - Vulnerability

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
July 1, 2026
Last Seen
July 1, 2026

Related Threat Clusters

  • Critical RCE Vulnerability Discovered in LLaMA-Factory WebUI

    A critical remote code execution vulnerability, CVE-2026-58116, has been identified in LLaMA-Factory versions up to 0.9.5. The flaw allows attackers to execute arbitrary Python code by supplying a malicious model path…

    3 articles · Updated July 1, 2026

Recent Intelligence Reports

  • Cvefeed High Severity Advisories Jun 30, 2026 CVE-2026-58116 - LLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path cvefeed.io Open source — cvefeed.io · July 1, 2026

CVSS v3.1 Breakdown