id: PYSEC-2026-2297 published: "2026-03-27T00:16:22.333Z" modified: "2026-07-13T05:52:25.049378Z" aliases: - CVE-2026-27893 - GHSA-7972-pg2x-xr59 details: vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the user's explicit `--trust-remote-code=False` security opt-out. This enables remote code execution via malicious model repositories even when the user has explicitly disabled remote code trust. Version 0.18.0 patches the issue. affected: - package: name: vllm ecosystem: PyPI purl: pkg:pypi/vllm ranges: - type: ECOSYSTEM events: - introduced: 0.10.1 - fixed: 0.18.0 versions: - 0.10.1 - 0.10.1.1 - 0.10.2 - 0.11.0 - 0.11.1 - 0.11.2 - 0.12.0 - 0.13.0 - 0.14.0 - 0.14.1 - 0.15.0 - 0.15.1 - 0.16.0 - 0.17.0 - 0.17.1 ecosystem_specific: {} references: - type: WEB url: https://access.redhat.com/security/cve/CVE-2026-27893 - type: WEB url: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27893.json - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2026:10140 - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2026:10141 - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2026:19712 - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2026:19724 - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2026:19725 - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2026:24977 - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2026:37275 - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2026:8746 - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2026:8747 - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2026:8748 - type: ADVISORY url: https://github.com/vllm-project/vllm/security/advisories/GHSA-7972-pg2x-xr59 - type: REPORT url: https://bugzilla.redhat.com/show_bug.cgi?id=2452055 - type: REPORT url: https://github.com/vllm-project/vllm/pull/36192 - type: FIX url: https://github.com/vllm-project/vllm/commit/00bd08edeee5dd4d4c13277c0114a464011acf72 severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H