vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 12 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False. | |
| Title | vLLM before 0.28.0 Remote Code Execution via LlavaOnevision2 processor | |
| First Time appeared |
Vllm
Vllm vllm |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vllm
Vllm vllm |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-12T12:08:56.821Z
Reserved: 2026-09-12T11:13:43.326Z
Link: CVE-2026-90553
No data.
Status : Received
Published: 2026-09-12T13:16:53.887
Modified: 2026-09-12T13:16:53.887
Link: CVE-2026-90553
No data.
OpenCVE Enrichment
Updated: 2026-09-12T15:45:16Z
Weaknesses