SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files
2026-04-21T01:24:04Z•f00cf0178c1266f7809e3961fd62976a54320a430412f52f05d6279727bd0a2e
ai-securitycommand-injectioncriticalcve-2026-5760ggufmodel-injectionpatchingrcesglangsupply-chain
What happened
CVE-2026-5760: a critical (CVSS 9.8) command-injection vulnerability in SGLang that allows remote code execution when a malicious GGUF-format model file is loaded by a vulnerable SGLang serving instance. An attacker can craft a GGUF model to trigger arbitrary command execution on the host running the model server, enabling full system compromise and downstream supply‑chain impact. Immediate mitigations include applying vendor patches/fixes, blocking untrusted model files, sandboxing model loading, restricting model‑server privileges and network access, validating model sources and checksums,/w
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- f00cf0178c1266f7809e3961fd62976a54320a430412f52f05d6279727bd0a2e
- Enrichment time
- 2026-04-21T01:24:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.