GHSA-359v-m36h-r94vCriticalCVSS 9.8
SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of...
🔗 CVE IDs covered (1)
📋 Description
SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.