VYPR

Inference

by Xorbitsai

Source repositories

CVEs (3)

  • CVE-2026-61539CriAug 21, 2026
    risk 0.58cvss 10.0epss 0.01

    Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/llama3_tool_parser.py and xinference/model/llm/utils.py.…

  • CVE-2026-76841HigAug 24, 2026
    risk 0.50cvss 8.8epss

    Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. Six loader call sites pass trust_remote_code=True as a literal or as an unconditional default: RerankModel._get_tokenizer in…

  • CVE-2025-3622MedApr 15, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects the function load of the file xinference/thirdparty/cosyvoice/cli/model.py. The manipulation leads to deserialization.