CVE-2026-58116: LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to ex
Remote code execution vulnerability allows attackers to execute arbitrary Python code.

1 CRIT · 5 HIGH · 1 INFO · THREAT RED · 7 items · Generated in 370s
Remote code execution vulnerability allows attackers to execute arbitrary Python code.
An unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap
A flaw in AIDC-AI ComfyUI-Copilot up to 2.0.28 allows remote attacks with high complexity.
A vulnerability in MLflow allows remote attacks with high complexity.
Path traversal vulnerability allows unauthenticated attackers to escape configured root directory and access sensitive files.
A vulnerability in Trail of Bits fickling versions up to and including 0.1.11 allows for pickle deserialization attacks.
A challenge to hack an AI assistant was run, with 6,000 attempts failing to leak secrets.