CVE-2026-58116Hiyouga · Llama-factory
Vulnerability data via NVD (ingested)
LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to execute arbitrary Python code by supplying a malicious model path in the Chat or Training interfaces. The application passes user-supplied model path input unvalidated into AutoTokenizer.from_pretrained() and AutoModel.from_pretrained() with a hardcoded trust_remote_code=True parameter, causing the Hugging Face transformers library to fetch and execute arbitrary code from a remote or local model repository with the privileges of the server process.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-58116product:"Hiyouga Llama-factory"http.html:"Llama-factory"More intel sources (5)
vuln:CVE-2026-58116vulnerabilities.cve_id: CVE-2026-58116CVE-2026-58116CVE-2026-58116"CVE-2026-58116" exploit -site:nvd.nist.gov