Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qwrp-wghp-94q2

Опубликовано: 18 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability

SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.

Пакеты

Наименование

sglang

pip
Затронутые версииВерсия исправления

>= 0.5.5, <= 0.5.12

Отсутствует

EPSS

Процентиль: 31%
0.00386
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-35

Связанные уязвимости

CVSS3: 9.1
nvd
3 месяца назад

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.

EPSS

Процентиль: 31%
0.00386
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-35