vllm: quen3: RCE in vllm tool call parser for qwen3coder
Published Aug 21, 2025
8.8
HIGHCVSS 3.1
EPSS 4.02%
Description
vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder
Affected products
No data.
No data.
No data.
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/deepseek-r1-0528-quantized-w4a16
Not affected
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/gemma-3n-e4b-it
Not affected
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/kimi-k2-instruct-quantized-w4a16
Not affected
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/modelcar-deepseek-r1-0528-quantized-w4a16
Not affected
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/modelcar-gemma-3n-e4b-it
Not affected
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/modelcar-kimi-k2-instruct-quantized-w4a16
Not affected
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/modelcar-qwen3-4b-quantized-w4a16
Not affected
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/modelcar-smollm3-3b
Not affected
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/qwen3-4b-quantized-w4a16
Not affected
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/smollm3-3b
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/deepseek-r1-0528-quantized-w4a16 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/gemma-3n-e4b-it | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/kimi-k2-instruct-quantized-w4a16 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/modelcar-deepseek-r1-0528-quantized-w4a16 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/modelcar-gemma-3n-e4b-it | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/modelcar-kimi-k2-instruct-quantized-w4a16 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/modelcar-qwen3-4b-quantized-w4a16 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/modelcar-smollm3-3b | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/qwen3-4b-quantized-w4a16 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/smollm3-3b | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability was discovered and fixed in the upstream qwen3 component. It never affected any Red Hat products. The impact is Important as it could allow remote code execution. The precondition of an attacker needing valid login credentials, prevents it from being critical.
References (8)
- https://access.redhat.com/security/cve/CVE-2025-9141 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2389395 Issue Tracking
- https://github.com/advisories/GHSA-79j6-g2m3-jgfw Advisory
- https://github.com/vllm-project/vllm/commit/4594fc3b281713bd3d7634405b4a1393af40d294
- https://github.com/vllm-project/vllm/pull/21396
- https://github.com/vllm-project/vllm/security/advisories/GHSA-79j6-g2m3-jgfw
- https://nvd.nist.gov/vuln/detail/CVE-2025-9141
- https://www.cve.org/CVERecord?id=CVE-2025-9141
Change history (0)
No recorded changes yet.