Skip to content
vLLMPYSEC-2026-3985

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with

High7.8CVE-2026-90553 · Published Sep 12, 2026 · updated Sep 17, 2026

Source advisory

Affected versions

PackageAffectedFixed in
vllm
PyPI
< 0.28.00.28.0

Changes since it was listed

DateChange
Sep 24Severity: Unrated to High
Details and references

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.

CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity from
NVD
Also known as
CVE-2026-90553, GHSA-3c86-2m5g-59q7

More vLLM advisories

All vLLM
DateAdvisory
Sep 8vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
CVE-2026-73560Medium6.5fixed in 0.26.0
Sep 8vLLM: Cross-User Data Leak Vulnerability
CVE-2026-73558Medium5.3fixed in 0.27.0
Sep 16vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
CVE-2026-57173Medium6.5fixed in 0.24.0
Sep 17vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
CVE-2026-69147Medium6.5fixed in 0.28.0
Sep 4vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
CVE-2026-73557Mediumfixed in 0.26.0
Sep 4vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) , missed sibling of GHSA-rwxx-mrjm-wc2m
CVE-2026-73556Medium5.3fixed in 0.26.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.