instructlab
PyPI2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting instructlabpage 1 of 1
- CVE-2026-6855HIGHCVSS 7.1EG 7.12026-04-22
vulnerable: 0.14.0 ... 0.26.1 (70 versions)
A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbi…
- CVE-2026-6859HIGHCVSS 8.8EG 8.82026-04-22
vulnerable: 0.14.0 ... 0.26.1 (70 versions)
A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from HuggingFace. This allows a remote attacker to achieve arbitrary Python code execution by convincing a user to run `ila…
Check whether instructlab is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for instructlab CVEs against the assets you own.
Start Free Scan →