CVE-2026-5760 is a critical remote code execution vulnerability affecting SGLang's reranking endpoint (/v1/rerank), which occurs when model files containing malicious tokenizer.chat_template configurations are loaded. The vulnerability stems from unsafe rendering of Jinja2 chat templates using an unsandboxed jinja2.Environment(), allowing attackers to execute arbitrary code on affected systems. This vulnerability impacts any deployment utilizing SGLang's reranking functionality with untrusted model files. The vulnerability carries a CVSS score of 9.8 (CRITICAL) with a network-based attack vector requiring no authentication, low complexity, and no user interaction, resulting in complete compromise of confidentiality, integrity, and availability. The attack surface is maximized as the vulnerability can be exploited remotely by any unauthenticated threat actor without special conditions or prerequisites. While the vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog, it remains on the active Hot List indicating ongoing community attention and concern. The EPSS score of 0.002870000 suggests relatively low current exploitation prevalence compared to other CVEs, though this should not diminish the critical nature of the vulnerability given its severity rating and potential impact on compromised systems. Organizations running SGLang should prioritize patching and implement network controls restricting access to the reranking endpoint.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.5.11CPE matchmatch criteria | cpe:2.3:a:lmsys:sglang:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.