Critical RCE and Path Traversal Vulnerabilities Found in SGLang Framework
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Three vulnerabilities have been identified in the SGLang framework, including two remote code execution (RCE) vulnerabilities and one path traversal vulnerability. These flaws allow unauthenticated attackers to execute arbitrary code or write files on affected systems. The vulnerabilities are tracked as CVE-2026-7301, CVE-2026-7302, and CVE-2026-7304, all published on 2026-05-18. Exploitation requires network access to the SGLang service, particularly when the multimodal generation mode is enabled. No patches are currently available, and the maintainers have not responded to disclosure attempts. The vulnerabilities stem from unsafe deserialization and improper handling of file uploads. Deployments exposing the affected interfaces to untrusted networks are at the highest risk. Security professionals are advised to monitor their systems closely until a patch is released.
Key Points: • Three critical vulnerabilities in SGLang allow RCE and path traversal attacks. • CVE-2026-7301 and CVE-2026-7304 enable RCE via unsafe deserialization. • No patches are available, and affected users should implement mitigations.