Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Xinference unauthenticated arbitrary-path file read vulnerability

Xinference v3.x contains an unauthenticated arbitrary-path file read vulnerability in the POST /v1/models/llm/auto-register endpoint that allows attackers to extract file contents from the server filesystem without authentication.

Disclosed 4 September 2026 · Record updated 13 September 2026

Impact

Unauthenticated attackers can read arbitrary files on affected servers by exploiting an unauthenticated endpoint that lacks path confinement.

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-xhf8-q5pf-vp28