Back

HIGH

vllm: quen3: RCE in vllm tool call parser for qwen3coder

Published Aug 21, 2025

Description

vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder

Affected products

Remediation

Red Hat statement

This vulnerability was discovered and fixed in the upstream qwen3 component. It never affected any Red Hat products. The impact is Important as it could allow remote code execution. The precondition of an attacker needing valid login credentials, prevents it from being critical.

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Published Aug 21, 2025

CISA Vulnrichment

No data

NVD

No data

Red Hat

Severity Important
Public date Aug 20, 2025
Bugzilla 2389395

ENISA EUVD

No data