CVE-2026-5760
CVSS 9.8 CRITICAL: sGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious…
Vulnerabilità ed exploit · Attacco ad app web
A model file can become a server compromise path when the serving stack renders attacker-controlled template data. In SGLang, the standard assumption that a downloaded GGUF model is just data breaks at the /v1/rerank endpoint, where a crafted tokenizer.chat_template can execute arbitrary Python code.
CERT/CC says CVE-2026-5760 is a CVSS 9.8 command-injection flaw in SGLang that affects the reranking endpoint /v1/rerank. The issue lets a malicious GGUF model trigger remote code execution in the SGLang service context, and the reported fix is to use ImmutableSandboxedEnvironment instead of jinja2.Environment().
The broader risk is that model-serving platforms can share the same parsing mistake. If one malicious GGUF file can compromise one framework, similar template-rendering paths in other LLM-serving projects may expose the same attack surface.
1 fonte · 21 apr
CVSS 9.8 CRITICAL: sGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious…
The Hacker News
SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files
CVE-2026-5760 (CVSS 9.8) exposes SGLang via /v1/rerank endpoint, enabling RCE through malicious GGUF models, risking server compromise.
originalePart of the PlainSec briefing for 2026-04-21
Every edition of this story: Malicious Model Files Can Own SGLang Servers