Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in Xinference, an API for running AI models. The flaw allows unauthenticated attackers to execute commands on the server hosting Xinference by sending specially crafted prompts. This could lead to a significant compromise of the server environment.
- Remote attackers can run commands on the server.
- This affects systems using Xinference for AI model inference.
- Confirm if Xinference is used and verify its version.
Attack Path
How an attacker could exploit the issue
An unauthenticated remote attacker can exploit this by sending a specially crafted prompt to the `/v1/chat/completions` endpoint. This prompt influences the output of a tool-calling feature, which is then processed by an `eval()` function. This allows the attacker to execute arbitrary commands on the server hosting Xinference.
- Network access required for interaction.
- Attacker-influenced output processed by `eval()`.
- Remote code execution on server.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an unauthenticated remote attacker to execute arbitrary commands on the Xinference server. When the server processes chat completions that include tool-use functionality, crafted input can lead to the evaluation of malicious Python expressions, potentially compromising the server's environment.
- Server process commands.
- Crafted prompts to eval() function.
- Arbitrary code execution.
Operational Fix
Recommended remediation, mitigation, and detection steps
Application owners and platform teams are likely responsible for addressing this vulnerability in Xinference, as it affects the inference API's handling of model outputs. The first practical step is to identify all Xinference deployments, determine their reachability and business criticality, and then assign ownership for remediation planning.
- Application and platform teams own the fix.
- Verify Xinference deployment reachability.
- Plan and coordinate remediation actions.