← לוח פגיעויות

CVE-2026-27893

גבוהה 8.8

תיאור (מקור, אנגלית)

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the user's explicit `--trust-remote-code=False` security opt-out. This enables remote code execution via malicious model repositories even when the user has explicitly disabled remote code trust. Version 0.18.0 patches the issue.

מדדים

CVSS 3.1
8.8 (HIGH) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
1% (אחוזון 100) נכון ל-26/7/2026
CWE
CWE-693, CWE-501

מוצרים מושפעים

vllm: vllm

קישורים