Hackers Could Weaponize GGUF Models to Achieve RCE on SGLang Inference Servers
ID: 64e7a396-6489-57df-8eb8-21b2a6e3b6a1
STIX ID: report--64e7a396-6489-57df-8eb8-21b2a6e3b6a1
Feed Name: Cyber Press
Threat Score
A critical SSTI vulnerability (CVE-2026-5760) in the SGLang framework allows attackers to achieve remote code execution by embedding malicious templates in GGUF model metadata; when a compromised model is loaded and the /v1/rerank endpoint renders the template using an insecure Jinja2.Environment, arbitrary OS commands can be executed — a PoC exists and administrators are advised to avoid untrusted models and adopt sandboxed template rendering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
