The Model Returned Python: CVE-2026-61539 and Tool-Parser RCE
CVE-2026-61539 turned attacker-influenced Llama tool output into Python RCE inside Xinference. This analysis traces the parser boundary, validates the primitive in a safe local lab, and maps durable detection and hardening controls.
