CVE-2026-5760
CVSS 9.8 CRITICAL: sGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious…
Vulnerabilità · 162 giorni fa
A model file can become a server compromise path when the serving stack renders attacker-controlled template data. In SGLang, the standard assumption that a downloaded GGUF model is just data breaks at the /v1/rerank endpoint, where a crafted tokenizer.chat_template can execute arbitrary Python code.
CERT/CC says CVE-2026-5760 is a CVSS 9.8 command-injection flaw in SGLang that affects the reranking endpoint /v1/rerank. The issue lets a malicious GGUF model trigger remote code execution in the SGLang service context, and the reported fix is to use ImmutableSandboxedEnvironment instead of jinja2.Environment().
The broader risk is that model-serving platforms can share the same parsing mistake. If one malicious GGUF file can compromise one framework, similar template-rendering paths in other LLM-serving projects may expose the same attack surface.
CVSS 9.8 CRITICAL: sGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious…
1 fonte che coprono questa storia
SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files
CVE-2026-5760 (CVSS 9.8) exposes SGLang via /v1/rerank endpoint, enabling RCE through malicious GGUF models, risking server compromise.
Part of the PlainSec briefing for 2026-04-21