logo

Critical 9.8 RCE Threat to SGLang AI Infrastructure

ID: d4d554e1-fe0d-593a-b33c-296d94fd2c6f

STIX ID: report--d4d554e1-fe0d-593a-b33c-296d94fd2c6f

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-04-21

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical RCE vulnerability (CVE-2026-5760, CVSS 9.8) was found in SGLang’s /v1/rerank endpoint: an attacker can craft a malicious GGUF model that embeds a Jinja2 server-side template injection via the tokenizer.chat_template field; when the model is loaded and the endpoint renders the template using jinja2.Environment() without sandboxing, arbitrary Python code executes on the host. The advisory warns of severe consequences (host takeover, lateral movement, data exfiltration, DoS), notes maintainers did not respond during coordination, and recommends switching to ImmutableSandboxedEnvironment as a temporary fix.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.