Externally Controlled Reference to a Resource in Another Sphere in vLLM - #VU134020
Published: June 9, 2026
vLLM
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper control of package resolution in docker/Dockerfile when building the Docker image with dependency installation from multiple package indexes. A remote attacker can publish a malicious package with the expected name and version on PyPI to execute arbitrary code.
User interaction is required to build the affected Docker image.