Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-4944

Опубликовано: 28 мая 2026
Источник: redhat
CVSS3: 8.8

Описание

vllm-project/vllm version 0.14.1 contains a vulnerability where the trust_remote_code=True parameter is hardcoded in two model implementation files (vllm/model_executor/models/nemotron_vl.py and vllm/model_executor/models/kimi_k25.py). This bypasses the user's explicit --trust-remote-code=False setting, enabling remote code execution via malicious HuggingFace model repositories. This issue is an incomplete fix for CVE-2025-66448 and CVE-2026-22807, as it affects separate code paths in model implementation files. Deployments loading NemotronVL or KimiK25 models are particularly impacted.

A flaw was found in vllm-project/vllm. A hardcoded setting in the model implementation files bypasses the user's explicit security configuration, which is intended to prevent the execution of remote code. This allows a remote attacker to achieve remote code execution by providing a malicious model from a HuggingFace repository. The vulnerability primarily impacts deployments loading NemotronVL or KimiK25 models, potentially leading to system compromise.

Отчет

Important: This flaw in vllm allows remote code execution by bypassing user-defined security configurations. Specifically, the trust_remote_code parameter is hardcoded to True when loading NemotronVL or KimiK25 models, enabling an attacker to execute arbitrary code via malicious HuggingFace model repositories. This impacts Red Hat AI Inference Server and Red Hat OpenShift AI deployments that utilize these specific models, as it overrides explicit --trust-remote-code=False settings.

Меры по смягчению последствий

To mitigate this issue, ensure that only trusted models are loaded into vllm deployments. Restrict network access to untrusted external HuggingFace model repositories to prevent the loading of malicious NemotronVL or KimiK25 models. This operational control reduces the attack surface by limiting the sources from which models can be obtained.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Will not fix
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9Will not fix
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-spyre-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Will not fix
Red Hat AI Inference Serverrhaii/vllm-cpu-rhel9Not affected
Red Hat AI Inference Serverrhaii/vllm-cuda-rhel9Not affected
Red Hat AI Inference Serverrhaii/vllm-gaudi-rhel9Will not fix
Red Hat AI Inference Serverrhaii/vllm-neuron-rhel9Will not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-547
https://bugzilla.redhat.com/show_bug.cgi?id=2482829vllm: vllm-project/vllm: Remote Code Execution via malicious HuggingFace model repositories

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
2 месяца назад

vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded in two model implementation files (`vllm/model_executor/models/nemotron_vl.py` and `vllm/model_executor/models/kimi_k25.py`). This bypasses the user's explicit `--trust-remote-code=False` setting, enabling remote code execution via malicious HuggingFace model repositories. This issue is an incomplete fix for CVE-2025-66448 and CVE-2026-22807, as it affects separate code paths in model implementation files. Deployments loading NemotronVL or KimiK25 models are particularly impacted.

CVSS3: 8.8
debian
2 месяца назад

vllm-project/vllm version 0.14.1 contains a vulnerability where the `t ...

CVSS3: 8.8
github
2 месяца назад

vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded in two model implementation files (`vllm/model_executor/models/nemotron_vl.py` and `vllm/model_executor/models/kimi_k25.py`). This bypasses the user's explicit `--trust-remote-code=False` setting, enabling remote code execution via malicious HuggingFace model repositories. This issue is an incomplete fix for CVE-2025-66448 and CVE-2026-22807, as it affects separate code paths in model implementation files. Deployments loading NemotronVL or KimiK25 models are particularly impacted.

8.8 High

CVSS3