CVE-2026-86169CWE-829

CVE-2026-86169

High · published September 5, 2026

CVSS v3.1
8.8
EPSS
0%
Percentile
39.9
In the wild
Unconfirmed
What it is

Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python code by crafting a malicious Hugging Face model repository selected as base_model, which is loaded with hardcoded trust_remote_code=True during AutoModelForCausalLM.from_pretrained.

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
8.7 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00483 · 39.9th percentile
Weakness
CWE-829 · Inclusion of Functionality from Untrusted Control Sphere
Published
2026-09-05T15:16Z
References (6)
EPSS history
Timeline
  • 07 SEP 03:36Z
    EPSS moved — → 0%
    epss
  • 05 SEP 11:01Z
    Axolotl through 0.18.0 Remote Code Execution via Multipack Patching
    cvelistv5