← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 12, 2026 · 13:16via CVEFeed

CVE-2026-90553 - vLLM before 0.28.0 Remote Code Execution via LlavaOnevision2 processor

Brief

CVE ID : CVE-2026-90553

Published : Sept. 12, 2026, 1:16 p. m.

  • 7 hours, 36 minutes ago

Description : vLLM before 0.

  • 0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2. py that executes with vLLM process authority even when trust_remote_code is set to False.

Severity: 8.5

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed→