Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
CVE-2026-5760
Vulnerability Description
SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment().
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
sglang 安全漏洞
Vulnerability Description
sglang是sgl-project开源的一个用于加速大模型推理的编程语言与运行时系统。 SGLang存在安全漏洞,该漏洞源于加载包含恶意tokenizer.chat_template的模型文件时,Jinja2聊天模板在无沙箱环境中渲染,可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A