← العودة للجدول
CVE-2026-5760
CVE-2026-5760 — VulnCheck: SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Exe
📅 2026-04-20
🔴 Critical 🔥 No VulnCheck Exploit Vulnerability CVSS 9.8

📋 الوصف الكامل

SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment().

💻 الأنظمة المتأثرة

VulnCheck: SGLang's reranking

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-5760

📡 المصدر

VulnCheck

✅ الحلول والتخفيف

Refer to CVE-2026-5760 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←