Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 30 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hiyouga
Hiyouga llama-factory |
|
| Vendors & Products |
Hiyouga
Hiyouga llama-factory |
Tue, 30 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 30 Jun 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to execute arbitrary Python code by supplying a malicious model path in the Chat or Training interfaces. The application passes user-supplied model path input unvalidated into AutoTokenizer.from_pretrained() and AutoModel.from_pretrained() with a hardcoded trust_remote_code=True parameter, causing the Hugging Face transformers library to fetch and execute arbitrary code from a remote or local model repository with the privileges of the server process. | |
| Title | LLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path | |
| Weaknesses | CWE-829 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-30T14:06:16.566Z
Reserved: 2026-06-29T14:13:18.383Z
Link: CVE-2026-58116
Updated: 2026-06-30T14:06:11.441Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-30T18:30:18Z