---
id: CVE-2025-66448
title: >-
  vllm: vLLM: Remote Code Execution via malicious model configuration
  (CVE-2025-66448)
summary: >-
  A remote code execution vulnerability has been identified in vLLM. An attacker
  can exploit a weakness in the model loading process to silently fetch and run
  unauthorized, malicious Python code on the host system. This happens because
  the e…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-94
vendor: Red Hat
product: Red Hat OpenShift AI 3.3
affected:
  - enterprise_linux_ai_rhel_ai
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - ai_inference_server 3.2
  - ai_inference_server 3.3
  - openshift_ai 2.25
  - openshift_ai 3.3
patched:
  - ai_inference_server 3.2
  - ai_inference_server 3.3
  - openshift_ai 2.25
  - openshift_ai 3.3
published: '2025-12-01'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T16:28:50+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-66448.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-66448.json
  - url: 'https://access.redhat.com/security/cve/CVE-2025-66448'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2418152'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-66448'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-66448'
  - url: >-
      https://github.com/vllm-project/vllm/commit/ffb08379d8870a1a81ba82b72797f196838d0c86
  - url: 'https://github.com/vllm-project/vllm/pull/28126'
  - url: >-
      https://github.com/vllm-project/vllm/security/advisories/GHSA-8fr4-5q9j-m8gm
  - url: 'https://access.redhat.com/errata/RHSA-2025:23080'
  - url: 'https://access.redhat.com/errata/RHSA-2025:23204'
  - url: 'https://access.redhat.com/errata/RHSA-2025:23078'
  - url: 'https://access.redhat.com/errata/RHSA-2026:3461'
  - url: 'https://access.redhat.com/errata/RHSA-2026:3462'
  - url: 'https://access.redhat.com/errata/RHSA-2025:23079'
  - url: 'https://access.redhat.com/errata/RHSA-2025:23449'
  - url: 'https://access.redhat.com/errata/RHSA-2025:23205'
  - url: 'https://access.redhat.com/errata/RHSA-2025:23209'
  - url: 'https://access.redhat.com/errata/RHSA-2026:30087'
  - url: 'https://access.redhat.com/errata/RHSA-2026:3782'
  - url: 'https://access.redhat.com/errata/RHSA-2026:3713'
  - url: 'https://access.redhat.com/errata/RHSA-2026:19712'
  - url: 'https://github.com/vllm-project/vllm'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.0066
epssPercentile: 0.49455
aliases:
  - GHSA-8fr4-5q9j-m8gm
  - PYSEC-2026-2015
ecosystem: pip
scores:
  vendor: 7.5
  osv: 7.1
ingestedAt: '2026-07-08T18:25:47.470Z'
---

## Overview

A remote code execution vulnerability has been identified in vLLM. An attacker can exploit a weakness in the model loading process to silently fetch and run unauthorized, malicious Python code on the host system. This happens because the engine mistakenly executes code from a remote repository referenced in a model's configuration, even when explicit security measures are set to prevent it.

## Vendor advisories

- **RHSA-2025:23080** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2025-12-10 · [advisory](https://access.redhat.com/errata/RHSA-2025:23080)
- **RHSA-2025:23204** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2025-12-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:23204)
- **RHSA-2025:23078** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2025-12-10 · [advisory](https://access.redhat.com/errata/RHSA-2025:23078)
- **RHSA-2026:3461** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-02-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:3461)
- **RHSA-2026:3462** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-02-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:3462)
- **RHSA-2025:23079** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2025-12-10 · [advisory](https://access.redhat.com/errata/RHSA-2025:23079)
- **RHSA-2025:23449** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2025-12-17 · [advisory](https://access.redhat.com/errata/RHSA-2025:23449)
- **RHSA-2025:23205** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2025-12-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:23205)
- **RHSA-2025:23209** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2025-12-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:23209)
- **RHSA-2026:30087** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-06-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:30087)
- **RHSA-2026:3782** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-03-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:3782)
- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux AI (RHEL AI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat Enterprise Linux AI (RHEL AI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-66448.json)

**vllm: vLLM: Remote Code Execution via malicious model configuration** — rated Important by Red Hat. Released 2025-12-01, updated 2026-09-21.

Affected:

- Red Hat Enterprise Linux AI (RHEL AI)
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)

Fixed:

- Red Hat AI Inference Server 3.2
- Red Hat AI Inference Server 3.3
- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.3

No fix planned:

- Red Hat Enterprise Linux AI (RHEL AI)
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)

Not affected:

- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.3

## Remediation

For more information visit https://access.redhat.com/errata/RHSA-2025:23080 https://access.redhat.com/errata/RHSA-2025:23080
For more information visit https://access.redhat.com/errata/RHSA-2025:23204 https://access.redhat.com/errata/RHSA-2025:23204
For more information visit https://access.redhat.com/errata/RHSA-2025:23078 https://access.redhat.com/errata/RHSA-2025:23078

Workarounds / mitigations:

- Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

## Package advisory (CVE-2025-66448)

Affected packages:

- `vllm < 0.11.1`

Patched in:

- `vllm 0.11.1`

Source: https://osv.dev/vulnerability/GHSA-8fr4-5q9j-m8gm
