Skip to content
SGLangGHSA-qwrp-wghp-94q2

SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability

Critical9.1CVE-2026-7302 · Published May 18, 2026 · updated Jun 29, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
sglang
PyPI
>= 0.5.5, <= 0.5.12No fix yet
Details and references

SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-35
Also known as
CVE-2026-7302, PYSEC-2026-538

More SGLang advisories

All SGLang
DateAdvisory
May 18SGLang: Unauthenticated RCE via --enable-custom-logit-processor
CVE-2026-7304Critical9.8no fix yet
May 18SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
CVE-2026-7301Critical9.8no fix yet
May 3SGLang has an Improper Input Validation/Injection Issue
CVE-2026-7669Medium5.6no fix yet
Jun 2SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
CVE-2026-10300Low3.7no fix yet
Jun 4SGLang is Vulnerable to DoS via the data_hash Function
CVE-2026-10775Low3.6no fix yet
Mar 12SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
CVE-2026-3989High7.8fixed in 0.5.10

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.