CVE-2026-7302Disclosure(lmsys / sglang)

LOWCVSS 9.1 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch lmsys sglang systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-35

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sglang

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
sglang

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-18: 3Patch / Workaround · 2026-05-18: 1Technical Details · 2026-05-18: 205-18
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
Full discourse3 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Multiple SGLang Vulnerabilities (CVE-2026-7301, CVE-2026-7302, CVE-2026-7304) Multiple critical flaws in SGLang may allow unauthenticated attackers to achieve remote code execution or arbitrary file writes through insecure deserialization, exposed ROUTER sockets, and path traversal in upload handling. Successful exploitation could lead to full server compromise in exposed AI inference deployments. 👉 Administrators should monitor vendor advisories and apply mitigations or patches as updates become available.

    Post summary

    The post announces three critical SGLang CVEs that enable remote code execution, file writes, and path traversal, while urging administrators to monitor advisories and apply patches.

    00020127
    255 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-7302 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7302 #CVE-2026-7302 #CVE   #CyberSecurity #InfoSec https://t.co/Gxz7gMbaka

    Post summary

    The tweet merely announces CVE‑2026‑7302 with a link to its NVD entry, lacking details on exploitation, patches, or technical characteristics.

    0000053
    160 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7302 Unauthenticated Path Traversal and Arbitrary File Write in SGLang Multimodal Generation Runtime https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7302

    Post summary

    The entry announces CVE‑2026‑7302, detailing an unauthenticated path traversal and arbitrary file write vulnerability in the SGLang Multimodal Generation Runtime, without mentioning any PoC, exploit code, or remediation steps.

    0000073
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applmsyssglang0.5.10--

Explore more