xinference@0.5.4 vulnerabilities

Model Serving Made Easy

Direct Vulnerabilities

Known vulnerabilities in the xinference package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Deserialization of Untrusted Data

xinference is a Xorbits Inference(Xinference) is a powerful and versatile library designed to serve language, speech recognition, and multimodal models. With Xorbits Inference, you can effortlessly deploy and serve your or state-of-the-art built-in models using just a single command. Whether you are a researcher, developer, or data scientist, Xorbits Inference empowers you to unleash the full potential of cutting-edge AI models.

Affected versions of this package are vulnerable to Deserialization of Untrusted Data through the load function that uses torch.load with weights_only default (false). An attacker can manipulate serialized data to execute arbitrary code by providing malicious input during the deserialization process.

How to fix Deserialization of Untrusted Data?

There is no fixed version for xinference.

[0,)