Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85668— Xinference 3.3.0 Unauthenticated Arbitrary-Path File Read via /v1/models/llm/auto-register

Quick assessment

Affected
xorbitsai inference
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Xinference(受影响提交 4a94832,v3.x 版本)中存在一个未经身份验证的任意路径文件读取漏洞,位于 POST /v1/models/llm/auto-register 端点。该端点接受调用方提供的 model_path 参数,但未进行身份验证或路径限制。此端点会在提供的路径下读取并解析 config.json、tokenizer_config.json 和 chat_template.jinja 文件,并将解析后的内容返回给调用方。这使得未经身份验证的攻击者能够探查服务器文件系统,并提取任意目录中

CVSS 7.5 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
xorbitsai inference ≤ 3.3.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85668

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Xinference 3.3.0 Unauthenticated Arbitrary-Path File Read via /v1/models/llm/auto-register
Source: CVE Program / CVE List V5
Vulnerability Description
Xinference (affected commit 4a94832, v3.x) contains an unauthenticated arbitrary-path file read vulnerability in the POST /v1/models/llm/auto-register endpoint, which accepts a caller-supplied model_path parameter without authentication or path confinement. The endpoint reads and parses config.json, tokenizer_config.json, and chat_template.jinja files at the supplied path and reflects the parsed content back to the caller, allowing an unauthenticated attacker to probe the server filesystem and extract content of files with those names in any directory.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
文件名或路径的外部可控制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
xorbitsai inference 0 ~ 3.3.0 -

II. Public POCs for CVE-2026-85668

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85668

登录查看更多情报信息。

Vendor Advisories for CVE-2026-85668 (1)

Other References for CVE-2026-85668 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-85668

No comments yet


Leave a comment