Inclusion of Functionality from Untrusted Control Sphere in vLLM - #VU146570
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to inclusion of functionality from an untrusted control sphere in the LlavaOnevision2 processor loader _load_ov2_processor when loading a crafted LlavaOnevision2 model. A remote attacker can supply malicious processor modules that are imported and executed to execute arbitrary code.
User interaction is required to load or serve the crafted model, and code runs with the authority of the vLLM process.