아래로 당겨서 돌아가기
AI Inference Framework SGLang Exposes RCE Vulnerability, Malicious GGUF Models Can Trigger Arbitrary Code Execution

AI Inference Framework SGLang Exposes RCE Vulnerability, Malicious GGUF Models Can Trigger Arbitrary Code Execution

AI Inference Framework SGLang Exposes RCE Vulnerability, Malicious GGUF Models Can Trigger Arbitrary Code Execution

開源大型語言模型推論框架SGLang被揭露存在嚴重遠端程式碼執行(RCE)漏洞CVE-2026-5760。攻擊者可製作內含惡意Jinja2模板注入惡意酬載(Payload)的GGUF模型檔,受害者一旦將模型載入SGLang,且有請求進入/v1/rerank端點,攻擊者就可能在目標伺服器上執行任意程式碼。