CVE-2026-90553 - vLLM before 0.28.0 Remote Code Execution via LlavaOnevision2 processor
Brief
CVE ID : CVE-2026-90553
Published : Sept. 12, 2026, 1:16 p. m.
- 7 hours, 36 minutes ago
Description : vLLM before 0.
- 0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2. py that executes with vLLM process authority even when trust_remote_code is set to False.
Severity: 8.5
- HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
