High severity8.8GHSA Advisory· Published Apr 22, 2026· Updated May 6, 2026
CVE-2026-6859
CVE-2026-6859
Description
A flaw was found in InstructLab. The linux_train.py script hardcodes trust_remote_code=True when loading models from HuggingFace. This allows a remote attacker to achieve arbitrary Python code execution by convincing a user to run ilab train/download/generate with a specially crafted malicious model from the HuggingFace Hub. This vulnerability can lead to complete system compromise.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
instructlabPyPI | <= 0.26.1 | — |
Affected products
3- Range: <= 0.26.1
- cpe:2.3:a:redhat:instructlab:-:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_ai:3.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- access.redhat.com/security/cve/CVE-2026-6859nvdVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-rxpq-xgqx-fr7pghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-6859ghsaADVISORY
News mentions
0No linked articles in our index yet.