External risk intelligence

Xinference Command Execution via eval() in Tool Parsing

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-61539

Xinference is designed as an inference API server. As a service providing chat completion endpoints, it is commonly deployed to be reachable by external applications or users to interact with hosted models, making its API endpoints a likely internet-facing service.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Xinference, an API for running AI models. The flaw allows unauthenticated attackers to execute commands on the server hosting Xinference by sending specially crafted prompts. This could lead to a significant compromise of the server environment.

  • Remote attackers can run commands on the server.
  • This affects systems using Xinference for AI model inference.
  • Confirm if Xinference is used and verify its version.

Attack Path

How an attacker could exploit the issue

An unauthenticated remote attacker can exploit this by sending a specially crafted prompt to the `/v1/chat/completions` endpoint. This prompt influences the output of a tool-calling feature, which is then processed by an `eval()` function. This allows the attacker to execute arbitrary commands on the server hosting Xinference.

  • Network access required for interaction.
  • Attacker-influenced output processed by `eval()`.
  • Remote code execution on server.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to execute arbitrary commands on the Xinference server. When the server processes chat completions that include tool-use functionality, crafted input can lead to the evaluation of malicious Python expressions, potentially compromising the server's environment.

  • Server process commands.
  • Crafted prompts to eval() function.
  • Arbitrary code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and platform teams are likely responsible for addressing this vulnerability in Xinference, as it affects the inference API's handling of model outputs. The first practical step is to identify all Xinference deployments, determine their reachability and business criticality, and then assign ownership for remediation planning.

  • Application and platform teams own the fix.
  • Verify Xinference deployment reachability.
  • Plan and coordinate remediation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Xinference and what is it used for?

Xinference is an open-source inference API server designed to host and interact with various AI models, including speech and multimodal systems. Developers and organizations use it to provide chat-based completion endpoints, allowing external applications or users to send prompts and receive responses from these AI models.

How does CVE-2026-61539 create a security risk?

This vulnerability is classified as CWE-95, or Improper Neutralization of Directives in Dynamically Evaluated Code. It occurs because the software uses the dangerous eval() function to process model outputs. By sending specific tool-calling prompts, an attacker can trick the system into executing arbitrary Python code directly on the server.

Do I need to be authenticated to trigger this vulnerability?

No. The vulnerability can be triggered by an unauthenticated remote attacker. It does not require login credentials or prior access to the system. Simply sending a crafted prompt to the /v1/chat/completions endpoint is enough to influence the tool-parsing logic and execute commands, provided the server is processing that input.

Is my Xinference instance at risk if it is internet-facing?

Yes. Halo Surface Signal identifies Xinference as an API service commonly deployed to be reachable by external applications. Because the service is intended for interaction, instances exposed to the internet are highly likely to be reachable by attackers, significantly increasing the risk of unauthorized remote command execution.

When should I update my Xinference deployment?

You should prioritize upgrading to version 2.7.0 or later immediately. The first step is to identify all running instances of Xinference, determine their network reachability, and confirm their current version. Since this flaw allows for full server compromise, coordinating a patch deployment is a critical security task.

References