PT-2026-41669 · Sglang · Sglang

CVE-2026-7302

·

Published

2026-05-18

·

Updated

2026-06-29

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions SGLangs multimodal generation runtime (affected versions not specified)
Description An unauthenticated path traversal flaw allows an attacker to write arbitrary files to any location where the server process has write permissions. This is achieved by including ../ sequences in the upload filename when sending requests to specific endpoints.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7302
GHSA-QWRP-WGHP-94Q2
PYSEC-2026-538

Affected Products

Sglang