Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Axolotl-ai-cloud
Axolotl-ai-cloud axolotl |
|
| Vendors & Products |
Axolotl-ai-cloud
Axolotl-ai-cloud axolotl |
Sat, 05 Sep 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python code by crafting a malicious Hugging Face model repository selected as base_model, which is loaded with hardcoded trust_remote_code=True during AutoModelForCausalLM.from_pretrained. | |
| Title | Axolotl through 0.18.0 Remote Code Execution via Multipack Patching | |
| Weaknesses | CWE-829 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-08T18:13:27.612Z
Reserved: 2026-09-05T10:39:12.130Z
Link: CVE-2026-86169
Updated: 2026-09-08T18:13:21.821Z
Status : Received
Published: 2026-09-05T11:16:45.703
Modified: 2026-09-08T19:20:09.813
Link: CVE-2026-86169
No data.
OpenCVE Enrichment
Updated: 2026-09-07T08:25:14Z