---
id: CVE-2026-61539
aliases:
  - GHSA-x2rj-828p-hx9m
  - PYSEC-2026-3946
title: >-
  Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3
  tool-call parsing
summary: >-
  Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3
  tool-call parsing
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
vendor: xinference
product: xinference
ecosystem: pip
affected:
  - xinference < 2.7.0
patched:
  - xinference 2.7.0
published: '2026-08-21'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T12:25:27.471125692Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-x2rj-828p-hx9m'
references:
  - url: >-
      https://github.com/xorbitsai/inference/security/advisories/GHSA-x2rj-828p-hx9m
  - url: 'https://github.com/xorbitsai/inference/pull/4786'
  - url: >-
      https://github.com/xorbitsai/inference/commit/1b3d220f342ce68d34cec4586d9409d457dadc42
  - url: 'https://github.com/xorbitsai/inference'
  - url: 'https://github.com/xorbitsai/inference/releases/tag/v2.7.0'
  - url: 'https://pypi.org/project/xinference'
  - url: 'https://github.com/advisories/GHSA-x2rj-828p-hx9m'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-61539'
tags:
  - osv
  - pip
  - ghsa
epss: 0.01226
epssPercentile: 0.67619
cwe:
  - CWE-95
ingestedAt: '2026-08-21T21:22:19.508Z'
---

## Overview

### Summary

Xinference used Python's unsafe `eval()` function when parsing Llama3 tool-call output generated by a large language model. Because the model output can be influenced by attacker-controlled prompts sent to the chat completion API, a remote attacker can craft prompts that cause the model to return a Python expression. Xinference then evaluates that expression on the server while post-processing the tool-call result. In the tested default deployment, authentication was not enabled, so the vulnerability was exploitable by an unauthenticated remote attacker through the `/v1/chat/completions` endpoint.

### Details

Users can interact with deployed models through Xinference's OpenAI-compatible `/v1/chat/completions` API. The request entry point is implemented in `xinference/api/restful_api.py`; non-streaming requests call the model instance's `chat()` method and return the inference result.

When the Transformers backend is used, inference results flow through the batching logic in `xinference/model/llm/transformers/core.py`. Non-streaming chat results are handled by `handle_chat_result_non_streaming()`. If the request contains a `tools` field, Xinference calls `_post_process_completion()` to parse tool-call output from the model response.

The Llama3 tool-call parser is implemented in `xinference/model/llm/tool_parsers/llama3_tool_parser.py`. In affected versions, `extract_tool_calls()` parsed model output with `eval()`:

```python
def extract_tool_calls(
    self, model_output: str
) -> List[Tuple[Optional[str], Optional[str], Optional[Dict[str, Any]]]]:
    try:
        data = eval(model_output, {}, {})
        return [(None, data["name"], data["parameters"])]
    except Exception:
        return [(model_output, None, None)]
```

The intended behavior was to convert a Python dictionary-like string generated by the model into a dictionary object. However, `eval()` executes the input as a Python expression, and `eval(model_output, {}, {})` is not a security sandbox. If an attacker can influence the model output through prompt injection or direct chat input, the attacker can cause the model to return an expression such as:

```python
__import__('os').system('touch /tmp/hacked')
```

When the expression reaches `eval()`, it is executed in the Xinference server process context. The harmless `touch /tmp/hacked` command can be replaced with other payloads, such as a reverse shell, malware download, sensitive file read, or lateral-movement payload.

### Score

Severity: Critical

CVSS v3.1: 10.0

Vector: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H`

Rationale:

- AV:N: the vulnerable API is remotely reachable over the network;
- AC:L: exploitation only requires a crafted chat-completion request and tool-call parameter;
- PR:N: the tested default configuration did not require authentication;
- UI:N: no user interaction is required;
- S:C: command execution can affect resources beyond the Xinference application boundary;
- C:H/I:H/A:H: remote code execution can fully compromise confidentiality, integrity, and availability.

### Credit

This vulnerability was discovered by:

- XlabAI Team of Tencent Xuanwu Lab (xlabai@tencent.com)
- Atuin Automated Vulnerability Discovery Engine
- Guannan Wang (wgnbuaa@gmail.com), Zhanpeng Liu (pkugenuine@gmail.com), Guancheng Li (lgcpku@gmail.com)

## Affected packages

- `xinference < 2.7.0`

## Remediation

Upgrade to a patched release:

- `xinference 2.7.0`
