GHSA-rp86-qf3f-pqfcHighCVSS 7.8

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2...

Published
September 12, 2026
Last Modified
September 12, 2026

🔗 CVE IDs covered (1)

📋 Description

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.

🔗 References (4)