drMurlly 🌐 🏖️ 💻[verified]@drMurllyDisclosure
The post reveals that CVE‑2025‑9141 is a real vulnerability in vLLM’s XML tool parser, where tool‑call arguments are sent straight to eval() and can execute code on the host. No patch, exploit code, or active exploitation evidence is provided.
Coder_Tx[verified]@coder_txDisclosure
The post discloses that CVE‑2025‑9141 exploits a vLLM XML tool‑call parser that passes parameters directly to eval(), enabling code execution via the model’s token output.
—[verified]@okey_amyDisclosure
CVE-2025-9141 is reported to allow LLM inference engines to execute arbitrary code on the host, but no exploit code, patch, or evidence of active exploitation is provided. The reference is a blog post, not a technical PoC.
AiDevCraft[verified]@AiDevCraftGeneral
The text announces the discovery of a CVE-2025-9141 remote code execution vulnerability in vLLM's Qwen3-Coder parser, but provides no evidence of exploitation, PoC, or mitigation.
Valvet Online@VALVETONLINEDisclosure
The post alerts to CVE‑2025‑9141, noting that vLLM processes tool arguments via eval(), but does not provide a PoC, exploit code, patch, or evidence of active exploitation.