← Vulnerability feed

Vulnerability record · CVE-2026-7302 · published 18 May 2026

CVE-2026-7302: Lmsys sglang vulnerability

Lmsys · Sglang

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.

9.1 CVSS 3.1 Critical EPSS 0.58% · top 54.5% CWE-35 · CWE-35
9.1CVSS 3.1 base score
0.58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-7302 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-15969Lmsys sglang deserialization of untrusted data vulnerabilitySGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary comma…EPSS 1.0%9.8CVE-2026-15971Lmsys sglang vulnerabilitySGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, ena…EPSS 0.73%9.8CVE-2026-15976Lmsys sglang deserialization of untrusted data vulnerabilitySGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from…EPSS 0.60%9.8CVE-2026-7301Lmsys sglang deserialization of untrusted data vulnerabilitySGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming…EPSS 0.60%9.8CVE-2026-7304Lmsys sglang deserialization of untrusted data vulnerabilitySGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabl…EPSS 0.88%9.8CVE-2026-5760Lmsys sglang code injection vulnerabilitySGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is load…EPSS 1.1%9.8CVE-2026-3059Lmsys sglang deserialization of untrusted data vulnerabilitySGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted dat…EPSS 1.3%9.8CVE-2026-3060Lmsys sglang deserialization of untrusted data vulnerabilitySGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deseri…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2026-7302), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.