tag
Trust-Remote-Code
Critical
LLaMA-Factory WebUI Remote Code Execution via Hardcoded `trust_remote_code` (CVE-2026-58116)
CVE-2026-58116·
LLaMA-Factory ([hiyouga/LLaMA-Factory](https://github.com/hiyouga/LLaMA-Factory)) — WebUI Chat and Training interfaces
unpatched
High
AI Model-Loader `trust_remote_code` Order-of-Operations RCE Simulation (CVE-2026-22807)
CVE-2026-22807·
AI inference/model-loading frameworks that resolve custom model classes via auto_map before validating trust_remote_code (pattern seen in vLLM/Transformers-style loaders)
unpatched