← Voltar à pesquisa de CVEs

CVE-2026-7302

SGLangs

Descrição

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.

CVSS 9.1EPSS 0.386%Risco 0.94
Ver fonte
Publicação
2026-05-18 12:16:16
Versões afetadas
unknown
Tipo
Core software
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H