CVE-2026-27893 affects vLLM, an inference and serving engine for large language models, specifically versions 0.10.1 through 0.17.x. The vulnerability stems from hardcoded `trust_remote_code=True` in sub-component loading, which bypasses explicit user security opt-outs and enables remote code execution via malicious model repositories. Rated 8.8 HIGH (CVSSv3.1), this issue has a network attack vector, low attack complexity, and requires user interaction, leading to high impacts on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, no public exploit code available in major databases, and it is not listed on CISA's KEV catalog, though it has received minor community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.10.1, < 0.18.0CPE matchmatch criteria | cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.