Critical 9.8 RCE Threat to SGLang AI Infrastructure
ID: d4d554e1-fe0d-593a-b33c-296d94fd2c6f
STIX ID: report--d4d554e1-fe0d-593a-b33c-296d94fd2c6f
Feed Name: securityonline.info
A critical RCE vulnerability (CVE-2026-5760, CVSS 9.8) was found in SGLang’s /v1/rerank endpoint: an attacker can craft a malicious GGUF model that embeds a Jinja2 server-side template injection via the tokenizer.chat_template field; when the model is loaded and the endpoint renders the template using jinja2.Environment() without sandboxing, arbitrary Python code executes on the host. The advisory warns of severe consequences (host takeover, lateral movement, data exfiltration, DoS), notes maintainers did not respond during coordination, and recommends switching to ImmutableSandboxedEnvironment as a temporary fix.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
