PT-2026-3865 · Hugging Face+1 · Hugging Face Auto Map+1

Arthurgervais

+1

·

Publicado

2026-01-21

·

Atualizado

2026-01-30

·

CVE-2026-22807

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vLLM versions 0.10.1 through 0.13.x
Description vLLM is an inference and serving engine for large language models (LLMs). The software loads Hugging Face auto map dynamic modules during model resolution without verifying trust remote code. This allows attacker-controlled Python code within a model repository or path to execute when the server starts. An attacker who can control the model repository or path can achieve arbitrary code execution on the vLLM host during model loading. This occurs before any request handling and does not require API access. The auto map resolution in vllm/model executor/models/registry.py and the execution of code through get class from dynamic module in vllm/transformers utils/dynamic module.py are relevant to this issue.
Recommendations Upgrade to vLLM version 0.14.0 or later. Audit any custom Hugging Face models loaded in your ML pipeline.

Exploit

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-22807
GHSA-2PC9-4J83-QJMR

Produtos afetados

Hugging Face Auto Map
Vllm