{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/model-inference/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-90553"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["vLLM (\u003c 0.28.0)","vLLM (\u003c 0.28.0)","vLLM (\u003c= 0.29.0)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","model-inference","supply-chain","denial-of-service","vllm","vulnerability"],"_cs_type":"advisory","_cs_vendors":["vLLM"],"content_html":"\u003cp\u003evLLM versions prior to 0.28.0 are susceptible to a high-severity remote code execution vulnerability (CVE-2026-90553) located within the LlavaOnevision2 processor loader. The vulnerability stems from a flaw in the loader logic that fails to respect the trust_remote_code configuration parameter when initializing remote processor classes. Under normal security configurations, setting trust_remote_code to False is intended to prevent the execution of arbitrary code from model repositories. However, in this implementation, the loader ignores this directive, enabling attackers to include malicious Python code within a crafted processing_llava_onevision2.py file inside a model. When the vLLM application attempts to load the malicious model, the embedded code executes with the privileges of the vLLM process. This flaw significantly impacts organizations deploying vLLM for model serving, as it allows arbitrary code execution even when users follow established security best practices.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full remote code execution within the environment running the vLLM process. This allows attackers to gain unauthorized access to the host, steal data, or pivot further into the internal network. The vulnerability affects all users and organizations utilizing vLLM for machine learning model inference who have not yet upgraded to version 0.28.0.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all vLLM deployments to version 0.28.0 or later immediately to patch CVE-2026-90553.\u003c/li\u003e\n\u003cli\u003eImplement strict access controls for model storage locations to prevent unauthorized modification of model files, including the processing_llava_onevision2.py script.\u003c/li\u003e\n\u003cli\u003eRun vLLM processes in isolated environments, such as containers or dedicated VMs with restricted filesystem and network access, to minimize the impact of potential RCE.\u003c/li\u003e\n\u003cli\u003ePerform integrity checks on model repositories before loading them into the vLLM inference engine.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-18T16:07:31Z","date_published":"2026-09-12T13:20:03Z","id":"https://feed.craftedsignal.io/briefs/2026-09-vllm-rce/","summary":"A vulnerability in vLLM versions prior to 0.28.0 allows remote code execution by bypassing the trust_remote_code parameter during the loading of malicious LlavaOnevision2 processor classes.","title":"Remote Code Execution in vLLM LlavaOnevision2 Processor Loader","url":"https://feed.craftedsignal.io/briefs/2026-09-vllm-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Model-Inference","version":"https://jsonfeed.org/version/1.1"}