A critical remote code execution vulnerability, CVE-2026-58116, has been identified in LLaMA-Factory versions up to 0.9.5. The flaw allows attackers to execute arbitrary Python code by supplying a malicious model path…
3 articles · Updated July 1, 2026
Recent Intelligence Reports
Cvefeed High Severity Advisories Jun 30, 2026 CVE-2026-58116 - LLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path cvefeed.io Open source— cvefeed.io · July 1, 2026