CVE-2026-5760Disclosure(lmsys / sglang)

CRITICALCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 28 mentions and remains active

Immediate actions

  • Patch lmsys sglang systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment().

8.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-94

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sglang

Threat summary

  • Active exploitation appears in 7 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 77 mentions across 18 observed days

What's happening

  • Active exploitation reported across 7 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 26 signals
  • Technical details provided in 62 signals
  • Disclosure: 49 classified signals
  • Peaked 16d ago at 28 mentions (2026-04-21); latest day: 1
  • 77 total mentions across 18 days

Affected systems

Vendors
Products
sglang

Deep dive

Activity timeline77 mentions / 18d
07142128Mentions · 2026-04-20: 23Mentions · 2026-04-21: 28Mentions · 2026-04-22: 5Mentions · 2026-04-23: 1Mentions · 2026-04-24: 1Mentions · 2026-04-25: 2Mentions · 2026-04-26: 1Mentions · 2026-04-27: 3Mentions · 2026-04-28: 1Mentions · 2026-04-29: 1Mentions · 2026-05-01: 1Mentions · 2026-05-04: 1Mentions · 2026-05-06: 1Mentions · 2026-05-08: 2Mentions · 2026-05-20: 1Mentions · 2026-05-23: 1Mentions · 2026-06-12: 3Mentions · 2026-08-03: 1PoC Mentioned / Linked · 2026-04-20: 2PoC Mentioned / Linked · 2026-04-21: 2PoC Mentioned / Linked · 2026-05-04: 1Exploit Tool / Code · 2026-04-20: 1Active Exploitation · 2026-04-20: 1Active Exploitation · 2026-04-21: 3Active Exploitation · 2026-04-24: 1Active Exploitation · 2026-04-27: 1Active Exploitation · 2026-05-04: 1Patch / Workaround · 2026-04-20: 3Patch / Workaround · 2026-04-21: 10Patch / Workaround · 2026-04-22: 4Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-05-01: 1Patch / Workaround · 2026-05-08: 2Patch / Workaround · 2026-05-23: 1Patch / Workaround · 2026-06-12: 1Patch / Workaround · 2026-08-03: 1Technical Details · 2026-04-20: 22Technical Details · 2026-04-21: 27Technical Details · 2026-04-22: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 2Technical Details · 2026-04-27: 3Technical Details · 2026-04-28: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-20: 1Technical Details · 2026-06-12: 204-2004-2104-2204-2304-2404-2504-2604-2704-2804-2905-0105-0405-0605-0805-2005-2306-1208-03
Signal classification5 categories
Disclosure
4963.6%
Patch
1519.5%
Active Exploitation
79.1%
General
45.2%
PoC
22.6%
Referenced assets34 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-2023
Active Exploitation1Disclosure19General1Patch1PoC1
2026-04-2128
Active Exploitation3Disclosure20General1Patch3PoC1
2026-04-225
Disclosure1Patch4
2026-04-231
Patch1
2026-04-241
Active Exploitation1
2026-04-252
Disclosure2
2026-04-261
General1
2026-04-273
Active Exploitation1Disclosure1Patch1
2026-04-281
Disclosure1
2026-04-291
General1
2026-05-011
Disclosure1
2026-05-041
Active Exploitation1
2026-05-061
Disclosure1
2026-05-082
Patch2
2026-05-201
Disclosure1
2026-05-231
Patch1
2026-06-123
Disclosure2Patch1
2026-08-031
Patch1
Full discourse20 posts
  • @stuub@stuub_
    PoC

    1st CVE of the year for me :D CVE-2026-5760 RCE in SGLang via unsandboxed Jinja2 chat template rendering Published a bare bones PoC alongside the CVE advisory, available on Github. enjoy. https://www.cve.org/CVERecord?id=CVE-2026-5760 https://github.com/Stuub/SGLang-0.5.9-RCE

    Post summary

    The message announces CVE‑2026‑5760, an RCE in SGLang caused by unsandboxed Jinja2 templates, and shares a bare‑bones PoC on GitHub, with no mention of active exploitation or patches.

    140143865
    361 followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files https://thehackernews.com/2026/04/sglang-cve-2026-5760-cvss-98-enables.html

    Post summary

    The text announces the SGLang CVE‑2026‑5760 vulnerability, providing severity and exploitation details without mentioning PoC, exploit code, or patches.

    210641.9K
    158.1K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    SGLang faces a critical 9.8 CVSS RCE flaw (CVE-2026-5760). Malicious GGUF models can hijack AI servers via unsandboxed Jinja2 templates. Learn how to fix it. #SGLang #AISecurity #RCE #DeepSeek #Mistral #GGUF #InfoSec #CyberSecurity https://securityonline.info/sglang-critical-rce-cve-2026-5760-ai-model-poisoning/ https://t.co/QoMh7TJlaY

    Post summary

    The tweet highlights a high‑severity CVE‑2026‑5760 RCE flaw in SGLang, noting malicious GGUF models abuse unsandboxed Jinja2 templates, and points to a resource that offers a fix.

    00062523
    12.5K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    Critical RCE in SGLang (CVE-2026-5760, CVSS 9.8) A malicious GGUF model → server-side template injection → full code execution. AI supply chain is the new attack surface. Treat models as untrusted input.

    Post summary

    The text announces a critical remote code execution vulnerability in SGLang (CVE‑2026‑5760) that can be triggered through a malicious GGUF model via server‑side template injection, highlighting a threat to the AI supply chain.

    00050213
    237 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical server-side template injection vulnerability in #SGLang. CVE-2026-5760 CVSS: 9.8. This vulnerability can exploited to achieve remote code execution. #RCE! #Patch #Patch #Patch

    Post summary

    A critical server‑side template injection flaw (CVE‑2026‑5760) in SGLang has been disclosed, rated CVSS 9.8 and capable of remote code execution, with no PoC, exploit code, or patch details provided.

    02110377
    7.2K followersView on X
  • SoEmailSecurity@Soemailsecurity
    Disclosure

    SGLang's CVE-2026-5760 vulnerability has a CVSS score of 9.8, allowing remote code execution via malicious GGUF model files. With a score that high, can you afford to wait until it's exploited? Don't wait until it happens to you #cybersecurity #vulnerabilitymanagement #infosec

    Post summary

    SGLang’s CVE‑2026‑5760 is a high‑severity remote code execution flaw via malicious GGUF model files, highlighted without reference to a PoC, exploit code, or patch, serving as a warning for potential exploitation.

    1002042
    69 followersView on X
  • Lucas@lucasverdan
    Disclosure

    🛑 SGLang CVE-2026-5760 turns malicious GGUF models into RCE CERT/CC says SGLang CVE-2026-5760 can turn malicious GGUF model files into remote code exec… 🔗 Details → https://invaders.ie/resources/blog/vulnerability/sglang-cve-2026-5760-turns-malicious-gguf-models-into-rce

    Post summary

    CERT/CC has disclosed that SGLang CVE‑2026‑5760 allows malicious GGUF model files to trigger remote code execution, emphasizing the vulnerability’s RCE nature.

    11010225
    312 followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    SGLangに重大(Critical)な脆弱性。CVE-2026-5760はCVSSスコア9.8で、悪意あるGGUFモデルからの遠隔コード実行。細工されたhttp://tokenizer.chat_templateパラメータからSSTIが刺さる。未修正。 https://thehackernews.com/2026/04/sglang-cve-2026-5760-cvss-98-enables.html

    Post summary

    The text announces a new critical vulnerability, CVE‑2026‑5760, affecting SGLang, detailing remote code execution via malicious GGUF models and SSTI through a crafted tokenizer parameter, with no patch yet available.

    01020741
    7.6K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Disclosure

    🚨 Critical RCE flaw in (CVE-2026-5760, CVSS 9.8) Malicious GGUF model file + Jinja2 SSTI → arbitrary Python execution → full server compromise 💡 Lesson: AI models are now an attack vector. Loading untrusted models = executing untrusted code ⚠️ Action: Never load models from untrusted sources. Use sandboxed environments (ImmutableSandboxedEnvironment) and isolate inference servers https://thehackernews.com/2026/04/sglang-cve-2026-5760-cvss-98-enables.html

    Post summary

    The post announces a critical RCE in CVE‑2026‑5760 caused by malicious GGUF model files triggering Jinja2 SSTI, offering mitigation advice but no PoC or evidence of active exploitation.

    00030357
    16.1K followersView on X
  • Clone Systems@CloneSystemsInc
    Disclosure

    Vulnerability Alert — SGLang CVE-2026-5760 (CVSS 9.8) allows remote code execution in SGLang via malicious GGUF model files. The flaw affects the /v1/rerank endpoint and can lead to arbitrary Python code execution. Avoid untrusted models and apply mitigations immediately. https://t.co/QrUTzZ1EFo

    Post summary

    CVE‑2026‑5760 is disclosed, granting remote code execution in SGLang through malicious GGUF model files on the /v1/rerank endpoint; users should avoid untrusted models and apply mitigations immediately.

    0002060
    260 followersView on X
  • Inferlume@inferlume_hq
    Disclosure

    🤖 SGLang has 3 unpatched RCEs. CVE-2026-5760: Load a malicious AI model → hit one endpoint → full server compromise. CERT/CC disclosed it. No patch. No vendor response. If your team runs SGLang with public-facing APIs — you're exposed right now.

    Post summary

    SGLang has been disclosed to contain three unpatched remote code execution flaws, including CVE‑2026‑5760, wherein a malicious AI model sent to a single endpoint can fully compromise the server. No patch or workaround is available yet.

    1001038
    1 followersView on X
  • SoEmailSecurity@Soemailsecurity
    Disclosure

    Source: SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files

    Post summary

    The snippet discloses a high‑severity RCE vulnerability (CVE‑2026‑5760) in SGLang that can be triggered by malicious GGUF model files, but offers no PoC, exploit code, or mitigation details.

    0002039
    69 followersView on X
  • Adriana Babino@ABabino
    Disclosure

    SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files https://thehackernews.com/2026/04/sglang-cve-2026-5760-cvss-98-enables.html via @TheHackersNews

    Post summary

    The tweet announces the discovery of CVE‑2026‑5760 in SGLang, with a high CVSS score of 9.8 and the ability to execute remote code through malicious GGUF model files; no active exploitation or patch information is provided.

    0002059
    120 followersView on X
  • キタきつね@foxbook
    Disclosure

    SGLang CVE-2026-5760 (CVSS 9.8) 悪意のあるGGUFモデルファイルを介してリモートコード実行が可能になる SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files #HackerNews (Apr 20) https://thehackernews.com/2026/04/sglang-cve-2026-5760-cvss-98-enables.html

    Post summary

    The text announces the disclosure of CVE‑2026‑5760, a high‑severity RCE vulnerability that can be triggered by malicious GGUF model files. No PoC, exploit tool, active exploitation, or mitigation details are provided.

    10010232
    4.8K followersView on X
  • motch | セキュリティ🛡️@motch_dev
    Disclosure

    🚨SGLangに緊急脆弱性🚨 CVE-2026-5760 (CVSS 9.8)が発見!悪意あるGGUFモデルファイルでRCEが可能に。大規模言語モデルを使う方は要注意️アップデートで対策を! あなたのシステムは大丈夫? #セキュリティ #脆弱性 https://t.co/d0eAGlsZSD

    Post summary

    CVE‑2026‑5760 is a newly discovered high‑severity RCE vulnerability triggered by malicious GGUF model files; immediate updates are recommended.

    1001068
    267 followersView on X
  • nakamura@tomoaxe
    Disclosure

    chat_templateに悪意ある仕込みって、こんなところも攻撃経路なるのか。。。 SGLang CVE-2026-5760 (CVSS 9.8) — 悪意あるGGUFモデルファイルでRCE https://thehackernews.com/2026/04/sglang-cve-2026-5760-cvss-98-enables.html

    Post summary

    The announcement highlights a newly disclosed high‑severity CVE (SGLang CVE‑2026‑5760) that enables remote code execution via malicious GGUF model files, but no proof of concept, exploit code, or patch details are included.

    10010360
    892 followersView on X
  • Paul Fregonese@paul_fregonese
    Disclosure

    📰 SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model… CVSS 9.8 via malicious model file load. GGUF as initial access vector is tradecraft gold for AI supply chain ops. https://thehackernews.com/2026/04/sglang-cve-2026-5760-cvss-98-enables.html #cybersecurity #infosec https://t.co/ncU01V4Sof

    Post summary

    The tweet announces a high‑severity CVE (CVE‑2026‑5760) in SGLang that allows remote code execution through a malicious GGUF model file, pointing out its potential for AI supply‑chain attacks without discussing patches or active exploitation.

    0002060
    50 followersView on X
  • SecureChap@SecureChap
    Disclosure

    SGLang's /v1/rerank endpoint executes arbitrary code from model files. CVE-2026-5760 affects the open-source LLM serving framework. CVSS 9.8. Reported by Stuart Beck and disclosed April 20, 2026 via CERT/CC. The vulnerable code sits in entrypoints/openai/serving_rerank.py. SGLang loads http://tokenizer.chat_template from GGUF models and renders it using jinja2.Environment() - an unsandboxed templating engine. Attacker crafts a malicious GGUF with a Jinja2 SSTI payload in the chat_template, uploads it to Hugging Face. Victim integrates the model into their SGLang setup. Unauthenticated POST to /v1/rerank forces rendering of the tainted chat_template. Server-side Python execution follows immediately. Exploitation hinges on Qwen3 reranker chat template phrasing. Maintainers ignored coordinated disclosure. No patch released. Swap to ImmutableSandboxedEnvironment for mitigation. A .gguf file blurs the line between data and code when loaders skip sandboxing.

    Post summary

    The post discloses a severe, unpatched CVE (CVE-2026-5760) affecting SGLang’s rerank endpoint, detailing its exploitation via Jinja2 SSTI and suggesting a workaround using ImmutableSandboxedEnvironment.

    1001086
    6 followersView on X
  • cyntelnext@cyntelnext
    Disclosure

    SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files - https://thehackernews.com/2026/04/sglang-cve-2026-5760-cvss-98-enables.html #model #malicious #sglang

    Post summary

    The post announces a new high‑severity RCE vulnerability in SGLang (CVE‑2026‑5760) that can be triggered by malicious GGUF model files, but it does not provide PoC, exploitation, or mitigation details.

    1001056
    21 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-5760 (CVSS 9.8, disclosed April 20, 2026) is a Server-Side Template Injection (SSTI) vulnerability triggered through the /v1/rerank endpoint when processing a maliciously crafted model file.

    Post summary

    A high‑severity SSTI vulnerability (CVE‑2026‑5760, CVSS 9.8) was disclosed, affecting model file processing via the /v1/rerank endpoint.

    1000039
    267 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applmsyssglang---

Explore more