vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out
High8.8CVE-2026-27893 · Published Mar 27, 2026 · updated Sep 10, 2026
### Summary Two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the user's explicit `--trust-remote-code=False` security opt-out. This enables remote code execution via malicious model repositories even when the user has explicitly disabled remote code trust. ### Details **Affected files (latest main branch):** 1. `vllm/model_executor/models/nemotron_vl.py:430` ```python vision_model = AutoModel.from_config(config.vision_config, trust_remote_code=True) ``` 2. vllm/model_executor/models/kimi_k25.py:177 ```python cached_get_image_processor(self.ctx.model_config.model, trust_remote_code=True) ``` Both pass a hardcoded trust_remote_code=True to HuggingFace API calls, overriding the user's global --trust-remote-code=False setting. Relation to prior CVEs: - CVE-2025-66448 fixed auto_map resolution in vllm/transformers_utils/config.py (config loading path) - CVE-2026-22807 fixed broader auto_map at startup - Both fixes are present in the current code. These hardcoded instances in model files survived both patches , different code paths. ### Impact Remote code execution. An attacker can craft a mal...
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| vllm PyPI | >= 0.10.1, < 0.18.0 | 0.18.0 |
Details and references
### Summary Two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the user's explicit `--trust-remote-code=False` security opt-out. This enables remote code execution via malicious model repositories even when the user has explicitly disabled remote code trust. ### Details **Affected files (latest main branch):** 1. `vllm/model_executor/models/nemotron_vl.py:430` ```python vision_model = AutoModel.from_config(config.vision_config, trust_remote_code=True) ``` 2. vllm/model_executor/models/kimi_k25.py:177 ```python cached_get_image_processor(self.ctx.model_config.model, trust_remote_code=True) ``` Both pass a hardcoded trust_remote_code=True to HuggingFace API calls, overriding the user's global --trust-remote-code=False setting. Relation to prior CVEs: - CVE-2025-66448 fixed auto_map resolution in vllm/transformers_utils/config.py (config loading path) - CVE-2026-22807 fixed broader auto_map at startup - Both fixes are present in the current code. These hardcoded instances in model files survived both patches , different code paths. ### Impact Remote code execution. An attacker can craft a malicious model repository that executes arbitrary Python code when loaded by vLLM, even when the user has explicitly set --trust-remote-code=False. This undermines the security guarantee that trust_remote_code=False is intended to provide. Remediation: Replace hardcoded trust_remote_code=True with self.config.model_config.trust_remote_code in both files. Raise a clear error if the model component requires remote code but the user hasn't opted in.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-693
- Also known as
- CVE-2026-27893, PYSEC-2026-2297
- github.com/vllm-project/vllm/security/advisories/GHSA-7972-pg2x-xr59
- nvd.nist.gov/vuln/detail/CVE-2026-27893
- github.com/vllm-project/vllm/pull/36192
- github.com/vllm-project/vllm/commit/00bd08edeee5dd4d4c13277c0114a464011acf72
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27893.json
- github.com/vllm-project/vllm
- github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2297.yaml
- bugzilla.redhat.com/show_bug.cgi?id=2452055
- access.redhat.com/security/cve/CVE-2026-27893
- access.redhat.com/errata/RHSA-2026:8748
- access.redhat.com/errata/RHSA-2026:8747
- access.redhat.com/errata/RHSA-2026:8746
- access.redhat.com/errata/RHSA-2026:37275
- access.redhat.com/errata/RHSA-2026:24977
- access.redhat.com/errata/RHSA-2026:19725
- access.redhat.com/errata/RHSA-2026:19724
- access.redhat.com/errata/RHSA-2026:19712
- access.redhat.com/errata/RHSA-2026:10141
- access.redhat.com/errata/RHSA-2026:10140
More vLLM advisories
All vLLM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 5 | vLLM Vulnerable to Remote DoS via Special-Token Placeholders | Medium6.5 | 0.20.0 |
| Apr 27 | vLLM makes Use of Uninitialized Resource | Low5.6 | 0.19.1 |
| Apr 3 | vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing | Medium6.5 | 0.19.0 |
| Apr 3 | vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url ` | Medium5.4 | 0.19.0 |
| Apr 3 | vLLM: Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server | Medium6.5 | 0.19.0 |
| Mar 9 | vLLM has SSRF Protection Bypass | Medium5.4 | 0.17.0 |