vLLMPYSEC-2026-3985
vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with
High7.8CVE-2026-90553 · Published Sep 12, 2026 · updated Sep 17, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| vllm PyPI | < 0.28.0 | 0.28.0 |
Changes since it was listed
| Date | Change |
|---|---|
| Sep 24 | Severity: Unrated to High |
Details and references
vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- NVD
- Also known as
- CVE-2026-90553, GHSA-3c86-2m5g-59q7
More vLLM advisories
All vLLM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections CVE-2026-73560Medium6.5fixed in 0.26.0 | Medium6.5 | 0.26.0 |
| Sep 8 | vLLM: Cross-User Data Leak Vulnerability CVE-2026-73558Medium5.3fixed in 0.27.0 | Medium5.3 | 0.27.0 |
| Sep 16 | vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions CVE-2026-57173Medium6.5fixed in 0.24.0 | Medium6.5 | 0.24.0 |
| Sep 17 | vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation CVE-2026-69147Medium6.5fixed in 0.28.0 | Medium6.5 | 0.28.0 |
| Sep 4 | vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts CVE-2026-73557Mediumfixed in 0.26.0 | Medium | 0.26.0 |
| Sep 4 | vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) , missed sibling of GHSA-rwxx-mrjm-wc2m CVE-2026-73556Medium5.3fixed in 0.26.0 | Medium5.3 | 0.26.0 |