CVE-2025-66448High· 7.5▾ TwilightA remote code execution vulnerability has been identified in vLLM. An attacker can exploit a weakness in the model loading process to silently fetch and run unauthorized, malicious Python code on the host system. This happens because the e…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.6%
0.6% → 0.7%
Last analysed / modified upstream
7.1 → 7.5
A remote code execution vulnerability has been identified in vLLM. An attacker can exploit a weakness in the model loading process to silently fetch and run unauthorized, malicious Python code on the host system. This happens because the engine mistakenly executes code from a remote repository referenced in a model's configuration, even when explicit security measures are set to prevent it.
vllm: vLLM: Remote Code Execution via malicious model configuration — rated Important by Red Hat. Released 2025-12-01, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
For more information visit https://access.redhat.com/errata/RHSA-2025:23080 https://access.redhat.com/errata/RHSA-2025:23080 For more information visit https://access.redhat.com/errata/RHSA-2025:23204 https://access.redhat.com/errata/RHSA-2025:23204 For more information visit https://access.redhat.com/errata/RHSA-2025:23078 https://access.redhat.com/errata/RHSA-2025:23078
Workarounds / mitigations:
Affected packages:
vllm < 0.11.1Patched in:
vllm 0.11.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-59425High· 7.5vllm: Timing Attack in vLLM API Token Verification Leading to Authentication Bypass (CVE-2025-59425)
CVE-2025-71408High· 7.0nltk: NLTK: Arbitrary Code Execution via Eval Injection in Collocations Module (CVE-2025-71408)
CVE-2025-53547High· 8.5helm.sh/helm/v3: Helm Chart Code Execution (CVE-2025-53547)
CVE-2025-69262High· 7.5pnpm is a package manager
CVE-2026-96889High· 7.8A flaw was found in librsvg
CVE-2024-56326High· 7.8Jinja has a sandbox breakout through indirect reference to format method