PT-2026-33769 · Sglang · Sglang
Published
2026-04-20
·
Updated
2026-04-20
·
CVE-2026-5760
CVSS v3.1
9.8
Critical
| AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment().
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sglang