CVE-2026-7669Disclosure

LOWCVSS 6.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation of the argument trust_remote_code with the input False as part of Boolean results in code injection. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. In get_tokenizer(), when the caller passes trust_remote_code=False and HuggingFace transformers v5 returns a TokenizersBackend instance (the generic fallback for tokenizer classes not in the registry), SGLang silently re-invokes AutoTokenizer.from_pretrained with trust_remote_code=True, overriding the caller's explicit security setting. A model repository containing a malicious tokenizer.py referenced via auto_map in tokenizer_config.json will execute arbitrary Python in the SGLang process during this second call. No log line or warning is emitted. The override affects all current SGLang versions because transformers==5.3.0 is pinned in pyproject.toml. Both tokenizer_mode="auto" and tokenizer_mode="slow" are affected. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Disclosures: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-02: 3Technical Details · 2026-05-02: 105-02
Signal classification3 categories
Disclosure
133.3%
Disclosures
133.3%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-7669 A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of t… https://www.cve.org/CVERecord?id=CVE-2026-7669 ----- Traducción: CVE-2026-7669 Se … http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-7669, noting its presence in sgl-project SGLang up to version 0.5.9 and the affected function, but provides no details on exploitation, patching, or technical specifics.

    00000105
    75 followersView on X
  • CVE@CVEnew
    Disclosures

    CVE-2026-7669 A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of t… https://www.cve.org/CVERecord?id=CVE-2026-7669

    Post summary

    The note reports that CVE‑2026‑7669 was found in SGLang up to version 0.5.9, affecting the get_tokenizer function, but offers no further details on exploitation, remediation, or technical characteristics.

    00000372
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7669 Unsafe Deserialization in SGLang HuggingFace Transformer Handler Up to 0.5.9 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7669

    Post summary

    The content announces CVE-2026-7669, highlighting unsafe deserialization in the SGLang HuggingFace Transformer Handler (v0.5.9 and earlier) with no evidence of exploitation, PoC, or patch details.

    0000052
    4.0K followersView on X

Explore more