<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T03:07:59.748141+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-27893</id>
    <title>CVE-2026-27893 — vLLM's hardcoded trust_remote_code=True in NemotronVL and KimiK25 bypasses user security opt-out</title>
    <updated>2026-10-03T03:07:59.750252+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> vllm-project vllm, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.3, Red Hat Enterprise Linux AI 3.3, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI 3.3, Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI)</p>
<p>vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the user's explicit `--trust-remote-code=False` security opt-out. This enables remote code execution via malicious model repositories even when the user has explicitly disabled remote code trust. Version 0.18.0 patches the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-27893"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7972-pg2x-xr59</id>
    <title>GHSA-7972-pg2x-xr59 — vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out</title>
    <updated>2026-10-03T03:07:59.750335+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vllm</p>
<p>### Summary</p>
<p>Two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the user's explicit `--trust-remote-code=False` security opt-out. This enables remote code execution via malicious model
  repositories even when the user has explicitly disabled remote code trust.</p>
<p>### Details</p>
<p>**Affected files (latest main branch):**</p>
<p>1. `vllm/model_executor/models/nemotron_vl.py:430`
  ```python
  vision_model = AutoModel.from_config(config.vision_config, trust_remote_code=True)
```</p>
<p>2. vllm/model_executor/models/kimi_k25.py:177
 
```python
  cached_get_image_processor(self.ctx.model_config.model, trust_remote_code=True)
```</p>
<p>Both pass a hardcoded trust_remote_code=True to HuggingFace API calls, overriding the user's global --trust-remote-code=False setting.</p>
<p>Relation to prior CVEs:
  - CVE-2025-66448 fixed auto_map resolution in vllm/transformers_utils/config.py (config loading path)
  - CVE-2026-22807 fixed broader auto_map at startup
  - Both fixes are present in the current code. These hardcoded instances in model files survived both patches — different code paths.</p>
<p>### Impact</p>
<p>Remote code execution. An attacker can craft a malicious model repository that executes arbitrary Python code when loaded by vLLM, even when the user has explicitly set --trust-remote-code=False. This undermines the security guarantee
  that trust_remote_code=False is intended to provide.</p>
<p>Remediation: Replace hardcoded trust_remote_code=True wi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7972-pg2x-xr59"/>
  </entry>
</feed>
