Inclusion of Functionality from Untrusted Control Sphere in vLLM - #VU146570

 

Inclusion of Functionality from Untrusted Control Sphere in vLLM - #VU146570

Published: September 1, 2026


Vulnerability identifier: #VU146570
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-829
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to inclusion of functionality from an untrusted control sphere in the LlavaOnevision2 processor loader _load_ov2_processor when loading a crafted LlavaOnevision2 model. A remote attacker can supply malicious processor modules that are imported and executed to execute arbitrary code.

User interaction is required to load or serve the crafted model, and code runs with the authority of the vLLM process.


Affected software

vLLM

Remediation

Install security update from vendor's website.

vLLM - update to 0.28.0

External References

Related Security Bulletins