SGLangGHSA-qwrp-wghp-94q2
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
Critical9.1CVE-2026-7302 · Published May 18, 2026 · updated Jun 29, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| sglang PyPI | >= 0.5.5, <= 0.5.12 | No fix yet |
Details and references
SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-35
- Also known as
- CVE-2026-7302, PYSEC-2026-538
More SGLang advisories
All SGLang| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 18 | SGLang: Unauthenticated RCE via --enable-custom-logit-processor CVE-2026-7304Critical9.8no fix yet | Critical9.8 | No fix yet |
| May 18 | SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket CVE-2026-7301Critical9.8no fix yet | Critical9.8 | No fix yet |
| May 3 | SGLang has an Improper Input Validation/Injection Issue CVE-2026-7669Medium5.6no fix yet | Medium5.6 | No fix yet |
| Jun 2 | SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice CVE-2026-10300Low3.7no fix yet | Low3.7 | No fix yet |
| Jun 4 | SGLang is Vulnerable to DoS via the data_hash Function CVE-2026-10775Low3.6no fix yet | Low3.6 | No fix yet |
| Mar 12 | SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization CVE-2026-3989High7.8fixed in 0.5.10 | High7.8 | 0.5.10 |