Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2026-90553

3 дня назад

A flaw was found in vLLM. The LlavaOnevision2 processor loader incorrectly ignores the `trust_remote_code` parameter, which is designed to prevent the execution of untrusted code. This oversight allows an attacker to craft a malicious model containing arbitrary code. When such a model is loaded, the code executes with the vLLM process's authority, leading to remote code execution.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-90553

3 дня назад

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-90553

3 дня назад

vLLM before 0.28.0 contains a remote code execution vulnerability in t ...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-rp86-qf3f-pqfc

3 дня назад

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-90553

A flaw was found in vLLM. The LlavaOnevision2 processor loader incorrectly ignores the `trust_remote_code` parameter, which is designed to prevent the execution of untrusted code. This oversight allows an attacker to craft a malicious model containing arbitrary code. When such a model is loaded, the code executes with the vLLM process's authority, leading to remote code execution.

CVSS3: 7.8
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-90553

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.

CVSS3: 7.8
0%
Низкий
3 дня назад
debian логотип
CVE-2026-90553

vLLM before 0.28.0 contains a remote code execution vulnerability in t ...

CVSS3: 7.8
0%
Низкий
3 дня назад
github логотип
GHSA-rp86-qf3f-pqfc

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.

CVSS3: 7.8
0%
Низкий
3 дня назад

Уязвимостей на страницу