CVE-2026-86169

Source
https://cve.org/CVERecord?id=CVE-2026-86169
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86169.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-86169
Published
2026-09-05T11:01:24.705Z
Modified
2026-09-06T03:47:37.849036494Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Axolotl through 0.18.0 Remote Code Execution via Multipack Patching
Details

Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trustremotecode defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python code by crafting a malicious Hugging Face model repository selected as basemodel, which is loaded with hardcoded trustremotecode=True during AutoModelForCausalLM.frompretrained.

Database specific
{
    "cwe_ids": [
        "CWE-829"
    ],
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86169.json"
}
References

Affected packages

Git / github.com/axolotl-ai-cloud/axolotl

Affected ranges

Type
GIT
Repo
https://github.com/axolotl-ai-cloud/axolotl
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.18.0"
        }
    ]
}

Affected versions

v0.*
v0.1.0
v0.10.0
v0.11.0
v0.12.0
v0.13.0
v0.13.1
v0.14.0
v0.15.0
v0.16.0
v0.16.1
v0.17.0
v0.18.0
v0.2.0
v0.2.1
v0.3.0
v0.4.0
v0.5.0
v0.5.1.post1
v0.5.2
v0.6.0
v0.7.0
v0.7.1
v0.8.0
v0.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86169.json"