logo

SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files

ID: 1ba30978-3225-5765-a1b2-3350a4d94ce1

STIX ID: report--1ba30978-3225-5765-a1b2-3350a4d94ce1

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-04-20

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A critical RCE vulnerability (CVE-2026-5760, CVSS 9.8) was disclosed in the SGLang LLM serving framework: a malicious GGUF model file can embed a Jinja2 SSTI payload in tokenizer.chat_template which, when the model is loaded and the /v1/rerank endpoint is invoked, is rendered with an unsandboxed jinja2.Environment() and executes arbitrary Python on the server. CERT/CC and the finder recommend switching to ImmutableSandboxedEnvironment to prevent exploitation; no vendor patch or response was reported in the advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.