Vulnerabilities
Vulnerable Software
Lmsys:  >> Sglang  >> 0.5.10  Security Vulnerabilities
SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet.
CVSS Score
9.8
EPSS Score
0.001
Published
2026-05-18
SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.
CVSS Score
9.1
EPSS Score
0.001
Published
2026-05-18
SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation.
CVSS Score
9.8
EPSS Score
0.004
Published
2026-05-18


Contact Us

Shodan ® - All rights reserved