Skip to content

Xinference security advisories

2 advisories · 1 critical or high in 12 months · latest Aug 21

2 advisories

DateAdvisory
Aug 21Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
CVE-2026-61539Critical10.0fixed in 2.7.0
Apr 22Malicious code in xinference (PyPI)
MAL-2026-3000Unratedno fix yet
About Xinference

Serve open models behind one API.

Packages watched: xinference (PyPI).

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.