logo

Hackers Could Weaponize GGUF Models to Achieve RCE on SGLang Inference Servers

ID: 64e7a396-6489-57df-8eb8-21b2a6e3b6a1

STIX ID: report--64e7a396-6489-57df-8eb8-21b2a6e3b6a1

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-04-21

Date Updated: 2026-04-21

Author: AnuPriya

...
...

A critical SSTI vulnerability (CVE-2026-5760) in the SGLang framework allows attackers to achieve remote code execution by embedding malicious templates in GGUF model metadata; when a compromised model is loaded and the /v1/rerank endpoint renders the template using an insecure Jinja2.Environment, arbitrary OS commands can be executed — a PoC exists and administrators are advised to avoid untrusted models and adopt sandboxed template rendering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.