<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:07:21 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-27893 — vLLM's hardcoded trust_remote_code=True in NemotronVL and KimiK25 bypasses user security opt-out</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-27893</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; vllm-project vllm, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.3, Red Hat Enterprise Linux AI 3.3, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI 3.3, Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI)&lt;/p&gt;
&lt;p&gt;vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the user&amp;#39;s explicit `--trust-remote-code=False` security opt-out. This enables remote code execution via malicious model repositories even when the user has explicitly disabled remote code trust. Version 0.18.0 patches the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; vllm-project vllm, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.3, Red Hat Enterprise Linux AI 3.3, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI 3.3, Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI)&lt;/p&gt;
&lt;p&gt;vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the user&amp;#39;s explicit `--trust-remote-code=False` security opt-out. This enables remote code execution via malicious model repositories even when the user has explicitly disabled remote code trust. Version 0.18.0 patches the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-27893</guid>
    </item>
    <item>
      <title>GHSA-7972-pg2x-xr59 — vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7972-pg2x-xr59</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vllm&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the user&amp;#39;s explicit `--trust-remote-code=False` security opt-out. This enables remote code execution via malicious model
  repositories even when the user has explicitly disabled remote code trust.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Affected files (latest main branch):**&lt;/p&gt;
&lt;p&gt;1. `vllm/model_executor/models/nemotron_vl.py:430`
  ```python
  vision_model = AutoModel.from_config(config.vision_config, trust_remote_code=True)
```&lt;/p&gt;
&lt;p&gt;2. vllm/model_executor/models/kimi_k25.py:177
 
```python
  cached_get_image_processor(self.ctx.model_config.model, trust_remote_code=True)
```&lt;/p&gt;
&lt;p&gt;Both pass a hardcoded trust_remote_code=True to HuggingFace API calls, overriding the user&amp;#39;s global --trust-remote-code=False setting.&lt;/p&gt;
&lt;p&gt;Relation to prior CVEs:
  - CVE-2025-66448 fixed auto_map resolution in vllm/transformers_utils/config.py (config loading path)
  - CVE-2026-22807 fixed broader auto_map at startup
  - Both fixes are present in the current code. These hardcoded instances in model files survived both patches — different code paths.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Remote code execution. An attacker can craft a malicious model repository that executes arbitrary Python code when loaded by vLLM, even when the user has explicitly set --trust-remote-code=False. This undermines the security guarantee
  that trust_remote_code=False is intended to provide.&lt;/p&gt;
&lt;p&gt;Remediation: Replace hardcoded trust_remote_code=True wi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vllm&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the user&amp;#39;s explicit `--trust-remote-code=False` security opt-out. This enables remote code execution via malicious model
  repositories even when the user has explicitly disabled remote code trust.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Affected files (latest main branch):**&lt;/p&gt;
&lt;p&gt;1. `vllm/model_executor/models/nemotron_vl.py:430`
  ```python
  vision_model = AutoModel.from_config(config.vision_config, trust_remote_code=True)
```&lt;/p&gt;
&lt;p&gt;2. vllm/model_executor/models/kimi_k25.py:177
 
```python
  cached_get_image_processor(self.ctx.model_config.model, trust_remote_code=True)
```&lt;/p&gt;
&lt;p&gt;Both pass a hardcoded trust_remote_code=True to HuggingFace API calls, overriding the user&amp;#39;s global --trust-remote-code=False setting.&lt;/p&gt;
&lt;p&gt;Relation to prior CVEs:
  - CVE-2025-66448 fixed auto_map resolution in vllm/transformers_utils/config.py (config loading path)
  - CVE-2026-22807 fixed broader auto_map at startup
  - Both fixes are present in the current code. These hardcoded instances in model files survived both patches — different code paths.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Remote code execution. An attacker can craft a malicious model repository that executes arbitrary Python code when loaded by vLLM, even when the user has explicitly set --trust-remote-code=False. This undermines the security guarantee
  that trust_remote_code=False is intended to provide.&lt;/p&gt;
&lt;p&gt;Remediation: Replace hardcoded trust_remote_code=True wi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7972-pg2x-xr59</guid>
    </item>
  </channel>
</rss>
