Skip to content
ThreatCluster

vLLM Vulnerability Allows Remote Code Execution via Malicious Payloads

First seen 2 Dec 2025, 18:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A vulnerability in vLLM versions 0.10.2 and later has been identified, allowing for remote code execution through malicious payloads. This flaw arises from improper handling of user-supplied prompt embeddings, potentially affecting users of the software.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (3)