sgl-project SGLang HuggingFace Transformer hf_transformers_utils.py get_tokenizer code injection
Published May 2, 2026
6.3
MEDIUMCVSS 4.0
EPSS 0.42%
Description
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation of the argument trust_remote_code with the input False as part of Boolean results in code injection. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. In get_tokenizer(), when the caller passes trust_remote_code=False and HuggingFace transformers v5 returns a TokenizersBackend instance (the generic fallback for tokenizer classes not in the registry), SGLang silently re-invokes AutoTokenizer.from_pretrained with trust_remote_code=True, overriding the caller's explicit security setting. A model repository containing a malicious tokenizer.py referenced via auto_map in tokenizer_config.json will execute arbitrary Python in the SGLang process during this second call. No log line or warning is emitted. The override affects all current SGLang versions because transformers==5.3.0 is pinned in pyproject.toml. Both tokenizer_mode="auto" and tokenizer_mode="slow" are affected. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
Affected
- 0.5.0
- 0.5.1
- 0.5.2
- 0.5.3
- 0.5.4
- 0.5.5
- 0.5.6
- 0.5.7
- 0.5.8
- 0.5.9
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Sgl-Project | SGLang | unknown | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26802 Advisory
- https://github.com/advisories/GHSA-6m5f-673f-5vh7 Advisory
- https://github.com/gouldnicholas/CVE-2026-7669-PoC exploit
- https://nvd.nist.gov/vuln/detail/CVE-2026-7669
- https://vuldb.com/submit/799263 third-party-advisory
- https://vuldb.com/vuln/360817 vdb-entrytechnical-descriptionexploit
- https://vuldb.com/vuln/360817/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26802 | Advisory | |
| https://github.com/advisories/GHSA-6m5f-673f-5vh7 | Advisory | |
| https://github.com/gouldnicholas/CVE-2026-7669-PoC | exploit | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-7669 | ||
| https://vuldb.com/submit/799263 | third-party-advisory | |
| https://vuldb.com/vuln/360817 | vdb-entrytechnical-descriptionexploit | |
| https://vuldb.com/vuln/360817/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub