#InstructLab
📌 CVE-2026-6859 - A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from HuggingFace. This allows a re... https://www.cyberhub.blog/cves/CVE-2026-6859
CVE-2026-6859
A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from HuggingFace. This allows a remote attacker to achieve arbitrary Python code execution by convincing a user to run `ilab train/download/generate` with a specially crafted malicious
www.cyberhub.blog
May 6, 2026 at 10:07 PM
🟠 CVE-2026-6859 - High (8.8)

A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` w...

https://www.thehackerwire.com/vulnerability/CVE-2026-6859/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
April 22, 2026 at 7:14 PM
InstructLabのchat session handlerにあるパス・トラバーサル脆弱性により、ローカル攻撃者は任意の場所にディレクトリ作成・ファイル書き込みが可能。
CVE-2026-6855 CVSS 7.1 | HIGH
NVD - CVE-2026-6855
nvd.nist.gov
April 22, 2026 at 4:10 PM
🚨 EUVD-2026-24752
📊 8.8/10
🏢 Red Hat

📝 A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from HuggingFace. This allows a remote...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24752

#cybersecurity #infosec #cve #euvd
April 22, 2026 at 3:01 PM
CVE-2026-6859 - Instructlab: instructlab: arbitrary code execution due to hardcoded `trust_remote_code=true`
CVE ID : CVE-2026-6859

Published : 22. April 2026 13:04 | 1 Stunde, 3 Minuten ago

Description : A flaw was found in InstructLab. The `linux_train.py` script hardc...
CVE-2026-6859 - Instructlab: instructlab: arbitrary code execution due to hardcoded `trust_remote_code=true`
A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from HuggingFace. This allows a remote attacker to achieve arbitrary Python code execution by convincing a user to run `ilab train/download/generate` with a specially crafted malicious model from the HuggingFace Hub. This vulnerability can lead to …
cvefeed.io
April 22, 2026 at 2:14 PM
🚨 EUVD-2026-24736
📊 7.1/10
🏢 Red Hat

📝 A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` ...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24736

#cybersecurity #infosec #cve #euvd
April 22, 2026 at 2:01 PM
Instructlab: instructlab: path traversal allows arbitrary directory creation ... A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session h...

Origin | Interest | Match
CVE-2026-6855 | THREATINT
CVE-2026-6855: A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbitrary locations on the ...
cve.threatint.eu
April 22, 2026 at 12:59 PM
1) Yeah, no. Containers aren’t VMs. Don’t confuse the 2.

2) Use ollama for local LLM execution (firget instructlab) but … why the need for obsidian?
October 19, 2025 at 3:24 AM
Presentation: GenAI at Scale: What It Enables, What It Costs, and How To Reduce the Pain

Mark Kurtz explains how to overcome the technical and financial hurdles of scaling GenAI. He shares how to optimize LLM deployments with open-source tools, including vLLM for efficient serving…

#ai #genai #llm
Presentation: GenAI at Scale: What It Enables, What It Costs, and How To Reduce the Pain
Mark Kurtz explains how to overcome the technical and financial hurdles of scaling GenAI. He shares how to optimize LLM deployments with open-source tools, including vLLM for efficient serving, LLM Compressor for model compression, and InstructLab for fine-tuning with synthetic data. He provides a deep dive into balancing performance, accuracy, and cost to ensure successful production deployment. By Mark Kurtz
www.infoq.com
September 8, 2025 at 11:42 PM
📢 Hi all! The #InstructLab Community is evolving to better align with technical changes, with the project components being separated and relocated. Here is the full announcement: blog.instructlab.ai/2025/09/inst...

Thank you for all your participation and contributions in the past year! 🐶
InstructLab Community Evolution – InstructLab
blog.instructlab.ai
September 8, 2025 at 10:31 AM
Discover how to make LLM fine-tuning accessible with InstructLab with this Devoxx UK talk by @cedricclyburn.bsky.social and Legare Kerrison. Learn to refine models for specific use cases on consumer hardware without needing data science expertise.

Watch here - www.devoxx.co.uk//talk?id=8092
June 26, 2025 at 2:02 PM
How to Make LLM fine-tuning accessible with InstructLab Even as AI technologies rapidly evolve, the foundational challenge remains: how can we make these systems understand and work with our specif...

#AI #InstructLab #Large #Language #Models #Red #Hat #AI #customization #Cedric #Clyburn […]
Original post on franksworld.com
www.franksworld.com
June 20, 2025 at 7:10 PM
InstructLab Research
The AI Innovation Team at Red Hat that builds InstructLab.
bit.ly
June 16, 2025 at 1:39 PM
Join us at AI Plumbers Conference on June 15 in Berlin!

From Red Hat, Marta and Karsten will present how to go from a notebook sketch to a production-ready LLM app using #opensource tools like Podman AI Lab and #InstructLab

Details and registration: lu.ma/vqx423ct
June 10, 2025 at 1:49 PM
Fine-tune LLMs with your own data using Apache Answer and InstructLab—no ML team or big infra needed. A practical AI guide for mid-sized teams. #finetuningllms
Fine-Tuning Models with Your Own Data, Effortlessly
hackernoon.com
May 15, 2025 at 3:28 AM
Making LLM fine-tuning accessible with InstructLab: 🖼️ Slides: red.ht/instructlab-slides
[Public] Easier & cost-effective model customization with InstructLab
Plug your knowledge into a model easily with InstructLab MLPrague: 2025 Tomas Tomecek Senior Principal Software Engineer @TomasTomecek Karel Piwko Senior Principal Software Engineer @karel.piwko Cedri...
red.ht
May 9, 2025 at 3:56 PM
📅 Starting next week:

Deep dive into Kubernetes resource management https://ku.bz/6Nw8j3m6y

From Your Local Machine to Kubernetes: Building AI Apps with Quarkus, InstructLab, and Podman AI Lab https://ku.bz/lspl1875L
May 8, 2025 at 3:36 PM
Fine-Tuning Models with Your Own Data, Effortlessly
Most blog posts focus on using top-tier LLMs or setting up complex AI pipelines for large corporations. But what if your data is private, and you don’t have access to top-tier ML talent or massive infrastructure? In this article, we show how to fine-tune a model for mid-sized software development teams or IT support, using your own domain expertise. With **Apache Answer** and **InstructLab** , you can build a powerful, cost-effective AI solution tailored to your specific needs. ## InstructLab InstructLab is an open-source AI community project aimed at empowering individuals to shape the future of generative AI. It provides tools for users to fine-tune existing large language models (LLMs), such as Granite, using additional data sources. This allows LLMs to continuously gain new knowledge, filling in gaps from their initial training, including real-time updates on current events. Subject matter experts from any domain can contribute to enhancing the LLMs' knowledge. InstructLab’s collaborative platform fosters community-driven improvements and offers tools for experimenting with model updates and ensuring their quality. LAB: Large-Scale Alignment for ChatBots The **taxonomy YAML** in InstructLab is a structured file that contains a set of **question-answer pairs** , organized by domain, to represent specific **skills or knowledge**. Each YAML file includes metadata like version, task description, contributor info, and example prompts. InstructLab uses these YAML files to **generate synthetic training data** that fine-tunes **open-weight models** like Qwen or DeepSeek. By aligning the model with curated, domain-specific content, InstructLab helps improve accuracy and relevance in the model's responses across specialized topics. ## Apache Answer Apache Answer is an open-source AI project that enables users to fine-tune large language models (LLMs) with custom data. Its tools facilitate continuous model improvement, allowing users to fill gaps in existing knowledge and incorporate new information. Apache Answer offers a flexible platform for experimenting with model updates, ensuring improved response quality. Designed for accessibility and collaboration, the project encourages contributions to the advancement of generative AI. Apache Answer is similar to Stack Overflow in that it provides a platform for users to ask and answer questions, especially in technical or specialized domains. However, **unlike Stack Overflow, Apache Answer is open source and can be fully self-hosted on-premises** , giving organizations complete control over their data, customization, and user access. While Stack Overflow is a public, centralized platform mainly focused on general programming and tech topics, **Apache Answer can be tailored to any industry or organization**. It allows companies to build their own internal knowledge-sharing platforms—whether for software engineering teams, legal departments, medical institutions, or customer support operations. In essence, Apache Answer offers the same collaborative Q&A experience as Stack Overflow but with **full ownership, flexibility, and adaptability** for private or specialized use. ## Synthetic data Synthetic data generation is crucial for industries where real-world data cannot be used due to privacy or regulatory concerns. **Apache Answer** , a Q&A platform similar to StackOverflow, allows organizations to gather relevant industry-specific data and insights from codebases or domain experts. This data can be leveraged for generating high-quality synthetic datasets tailored to specific business needs. **InstructLab** enhances this process by fine-tuning models to produce contextually accurate synthetic data, ensuring it reflects real-world scenarios. Combined with **RAG** (Retrieval-Augmented Generation) and **CAG** (Cache-Augmented Generation), **InstructLab** enables both real-time and cached synthetic data generation. YAML files produced by **Apache Answer** contain structured question-answer data that can be used to **fine-tune open-source language models**. By feeding this data into training workflows, models like **Qwen** or **DeepSeek** can be aligned with specific domains or organizational knowledge, improving their accuracy and relevance. Example YAML Q&A ## RAG & CAG **RAG** (Retrieval-Augmented Generation) is an AI method that finds the most up-to-date information from external sources every time a question is asked. It combines a search system with a language model so the answers are both current and accurate. **CAG** (Cache-Augmented Generation) is different. It collects and stores all the needed information in advance. The model then uses this stored data to give fast answers without needing to search each time. With **RAG** , InstructLab helps improve the model’s ability to follow instructions _after_ retrieving fresh information. Since RAG fetches real-time data, the model needs to blend that information into a clear, helpful response. InstructLab’s fine-tuning methods make the model better at using that external content effectively. With **CAG** , where information is pre-loaded into a cache, InstructLab helps train the model to give accurate and helpful answers _from that fixed data_. It can improve how well the model uses the cached knowledge by fine-tuning it on examples that mirror expected questions and answers, ensuring faster and more relevant results. In short, InstructLab makes models better at following instructions and delivering useful answers — whether the data comes in real-time (RAG) or from a pre-built cache (CAG). ## Deployment InstructLab can be installed locally using `pip` or the `uv` package manager, making it easy to set up for individual use or testing. Alternatively, it can run inside a Docker container, providing a consistent environment for development and deployment. For scalable production environments, InstructLab can also be deployed on Kubernetes, leveraging its orchestration capabilities to handle scaling and resource management efficiently. This flexibility ensures it adapts to various workflows, from local experimentation to large-scale distributed deployments. To deploy InstructLab on Kubernetes, use a Makefile to define and manage Kubernetes resources like Deployments and ConfigMaps as multi-line variables. Dynamically generate labels and annotations using Git metadata and environment variables. Validate configurations, enforce constraints, and apply manifests with `kubectl`. This approach avoids Helm's complexity while maintaining flexibility and transparency. Time to replace Helm: Back to the Future git clone https://github.com/avkcode/InstructLab.git Using kubectl: kubectl apply -f instructlab.yaml Using make: make => InstructLab Management System Available targets: Deployment: deploy - Deploy InstructLab with ConfigMap undeploy - Remove InstructLab deployment Interaction: logs - View container logs status - Show deployment status Utility: help - Show this help message With tools like **Apache Answer** and **InstructLab** , you can fine-tune models using your domain knowledge without needing vast resources. You don't need to be a large corporation or have a huge ML team to harness the power of AI for your specific needs.
forem.com
May 7, 2025 at 7:24 AM
Check out the AI track sessions on #RHSummit Community Day! events.experiences.redhat.com/widget/redha...

We have topics ranging from #Docling to #TrustyAI, inferencing to features stores, topped with your favourite #InstructLab tools & #Granite models. Register & add the sessions to your schedule!
Red Hat Summit 2025
Red Hat Summit is the premier enterprise open source event for IT professionals
events.experiences.redhat.com
April 30, 2025 at 8:56 PM
InstructLab Core v0.22.2
🫵 adds llama-cpp-python v0.3.2 meaning we now support Granite 3.0 GGUF models
🫵 adds a new config class, so please run ilab config init for proper functionality
bit.ly/4h57I70
#instructlab #genai #rhelai
InstructLab Core v0.22.2 Release
announce
bit.ly
April 30, 2025 at 5:08 AM
We'll be at #fossnorth in #Gothenburg next week, April 14-15! Learn about #InstructLab in the hands-on workshop on day 1 with @cybette.bsky.social

foss-north.se/2025/schedul...
foss-north 2025
foss-north.se
April 11, 2025 at 8:32 PM