THREAT OPS › Threat News › [NVD] CVE-2026-86169 (HIGH 8.8) — Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python code by crafting a malicious Hugging Face
[NVD] CVE-2026-86169 (HIGH 8.8) — Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python code by crafting a malicious Hugging Face
CVE-2026-86169 CVSS: 8.8 HIGH Published: 2026-09-05T11:16:45.703
Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python code by crafting a malicious Hugging Face model repository selected as base_model, which is loa
Indicators of compromise
- CVE-2026-86169cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86169