CVE-2025-9141Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-08-25); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-08-24: 1Mentions · 2026-08-25: 3Mentions · 2026-09-03: 1Technical Details · 2026-08-24: 1Technical Details · 2026-08-25: 3Technical Details · 2026-09-03: 108-2408-2509-03
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-08-241
Disclosure1
2026-08-253
Disclosure2General1
2026-09-031
Disclosure1
Full discourse5 posts
  • drMurlly 🌐 🏖️ 💻@drMurlly
    Disclosure

    Real CVE-2025-9141, not theory: vLLM shipped an XML tool parser for @Alibaba_Qwen's Qwen3 Coder that passed tool-call args straight to eval(). The model's own output tokens could execute code on the machine serving it. Who is auditing your inference stack?

    Post summary

    The post reveals that CVE‑2025‑9141 is a real vulnerability in vLLM’s XML tool parser, where tool‑call arguments are sent straight to eval() and can execute code on the host. No patch, exploit code, or active exploitation evidence is provided.

    0003094
    797 followersView on X
  • Coder_Tx@coder_tx
    Disclosure

    CVE-2025-9141 tam bunu gösterdi. vLLM'in Qwen3 Coder için yazdığı XML tool-call parser'ı, gelen parametreleri neredeyse doğrudan eval() fonksiyonuna veriyordu. Yani model ürettiği token dizisiyle sunucuda kod çalıştırabiliyordu.

    Post summary

    The post discloses that CVE‑2025‑9141 exploits a vLLM XML tool‑call parser that passes parameters directly to eval(), enabling code execution via the model’s token output.

    1000021
    86 followersView on X
  • —@okey_amy
    Disclosure

    vllm used eval on tool-call parameters cve-2025-9141 let the llm execute arbitrary code on the host machine gemini flagged the pr the maintainer force-merged it anyway https://boydkane.com/essays/llms-could-control-their-host-machines-by-exploiting-inference-engines

    Post summary

    CVE-2025-9141 is reported to allow LLM inference engines to execute arbitrary code on the host, but no exploit code, patch, or evidence of active exploitation is provided. The reference is a blog post, not a technical PoC.

    0000040
    304 followersView on X
  • Valvet Online@VALVETONLINE
    Disclosure

    CAN YOUR LLM TAKE OVER ITS OWN SERVER? 1. CVE-2025-9141: vLLM ran tool args through eval() 2. Gemini flagged the PR critical. Maintainer force-merged it 3. Exploit tokens in files can hit any LLM that reads them #LLM #AISecurity #vLLM https://t.co/tEGcAkqc9w

    Post summary

    The post alerts to CVE‑2025‑9141, noting that vLLM processes tool arguments via eval(), but does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    0000046
    66 followersView on X
  • AiDevCraft@AiDevCraft
    General

    An AI reviewer flagged the eval() as a critical RCE 92 seconds after the PR opened. Force-merged 4 hours later - "to unblock model usage." 30 days on: CVE-2025-9141, remote code execution in vLLM's Qwen3-Coder tool parser. Detection was never the bottleneck. https://t.co/XQ9H5SKr3G

    Post summary

    The text announces the discovery of a CVE-2025-9141 remote code execution vulnerability in vLLM's Qwen3-Coder parser, but provides no evidence of exploitation, PoC, or mitigation.

    0000072
    247 followersView on X

Explore more