Unauthenticated Arbitrary-Path File Read Vulnerability in Xinference by Xorbits AI
CVE-2026-85668

8.7HIGH

Key Information:

Vendor

Xorbitsai

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-85668?

Xinference contains a vulnerability that allows unauthenticated attackers to read arbitrary files from the server's filesystem. Specifically, the POST /v1/models/llm/auto-register endpoint accepts a caller-supplied model_path parameter without proper authentication or path validation. This oversight enables malicious actors to probe the server for sensitive information by reading files such as config.json, tokenizer_config.json, and chat_template.jinja from any accessible directory. As a result, this vulnerability compromises the file system integrity of the affected installations.

Affected Version(s)

inference 0 <= 3.3.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.