Skip to content
SGLangGHSA-9w53-xr52-mwgj

SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor

Medium7.3CVE-2025-10164 · Published Sep 9, 2025 · updated Jul 7, 2026

A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

GitHub advisory

Affected versions

PackageAffectedFixed in
sglang
PyPI
< 0.5.40.5.4
Details and references

More SGLang advisories

All SGLang
Advisory
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
Critical9.1May 18
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
Critical9.8May 18
SGLang has an Improper Input Validation/Injection Issue
Medium5.6May 3
SGLang: remote code execution
Critical9.8Mar 12
SGLang: remote code execution
Critical9.8Mar 12
SGLang: unsafe deserialization
High7.8Mar 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.