Pull down to go back
Critical RCE Vulnerability Discovered in SGLang AI Inference Framework—Malicious GGUF Models Can Execute Arbitrary Code

Critical RCE Vulnerability Discovered in SGLang AI Inference Framework—Malicious GGUF Models Can Execute Arbitrary Code

AI推論框架SGLang曝RCE漏洞,惡意GGUF模型可觸發任意程式碼執行

A severe remote code execution (RCE) vulnerability (CVE-2026-5760) has been discovered in SGLang, a popular open-source inference framework for large language models. Attackers can craft malicious GGUF model files containing Jinja2 template injection payloads. When a victim loads the model into SGLang and makes requests to the /v1/rerank endpoint, the attacker gains the ability to execute arbitrary code on the target server. This is a critical security issue for anyone running SGLang in production environments.