Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-90553

Опубликовано: 12 сент. 2026
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.

EPSS

Процентиль: 11%
0.00207
Низкий

7.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.8
redhat
3 дня назад

A flaw was found in vLLM. The LlavaOnevision2 processor loader incorrectly ignores the `trust_remote_code` parameter, which is designed to prevent the execution of untrusted code. This oversight allows an attacker to craft a malicious model containing arbitrary code. When such a model is loaded, the code executes with the vLLM process's authority, leading to remote code execution.

CVSS3: 7.8
debian
3 дня назад

vLLM before 0.28.0 contains a remote code execution vulnerability in t ...

CVSS3: 7.8
github
3 дня назад

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.

EPSS

Процентиль: 11%
0.00207
Низкий

7.8 High

CVSS3

Дефекты

CWE-94