CVE-2026-7302CRITICAL 9.1EPSS p30.3%

CVE-2026-7302CVE-2026-7302

Description

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.

Scoring

CVSS 3.19.1 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS0.39% probability of exploitation · percentile 30.3% · 2026-06-19T12:03:05Z
Published2026-05-18
Last modified2026-05-19

Underlying weaknesses· 1

CWE-35

References

  1. https://antiproof.ai/blog/three-rces-in-sglang/
  2. https://github.com/sgl-project/sglang/tree/main/python/sglang

1

TypeTargetConfidenceTier
WeaknessPath Traversal: '.../...//'cwe-350%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-7304
CVE
CVE-2026-3059
CVE
CVE-2026-5027
CVE
CVE-2026-21628
CVE
CVE-2026-2701
CVE
CVE-2025-3365
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.