Solutions  ·  2026-09-06

CVE-2026-85668 — Xinference unauthenticated arbitrary-path file read via auto-register endpoint

SolutionsMedium impactGlobal
VulnCheck (CNA) published CVE-2026-85668 on Sept 4, 2026, a CVSS 4.0 8.7 (High) unauthenticated arbitrary-path file-read vulnerability in Xinference (through v3.3.0) via the /v1/models/llm/auto-register REST endpoint, which reads and reflects config.json, tokenizer_config.json, and chat_template.jinja contents from a caller-supplied path without authentication or path confinement.
Highlights that AI inference-serving frameworks expose management/registration endpoints with production-infrastructure-grade attack surface (unauthenticated remote file disclosure), reinforcing that AI-platform services need the same exposure-management discipline as any internet-facing service.
MLOps/platform security teams running Xinference should immediately restrict external reachability of the auto-register endpoint, enforce authentication, and confine model paths pending a patched release.
VulnCheck AdvisoryCVE.org
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →