ThreatCluster

vLLM Vulnerability Allows Remote Code Execution via Malicious Payloads

First seen 2 Dec 2025, 18:33 UTC GbhackersCybersecuritynewsCyberpress 39

Article Content

Browse articles
ThreatCluster

A vulnerability in vLLM versions 0.10.2 and later has been identified, allowing for remote code execution through malicious payloads. This flaw arises from improper handling of user-supplied prompt embeddings, potentially affecting users of the software.