Database/AI/ML frameworks & serving
Docker Model Runner (vllm-metal backend): `trust_remote_code=True` set unconditionally, no sandbox
CVSS 8.2CVE-2026-5817AI/ML frameworks & servingcurated
Impact
trust_remote_code=True set unconditionally, no sandbox → tokenizer code executes
Who can reach it
Customer-supplied model repo
What to do
Rebuild/patch; no operator config can disable it
References
Related entries
- GitLab AI Gateway: crafted inline flow config overrides the HTTP Host header and leaks Vertex credentialsCVE-2026-75871 · GitLab AI Gateway (Duo Agent Platform inline flow configuration)High
- Gradio: Command injectionCVE-2023-6572 · GradioHigh
- LangChain: Directory traversal via the template path parameterCVE-2024-28088 · LangChainHigh
- JupyterHub: Malicious subdomain tricks a userCVE-2024-28233 · JupyterHubHigh
- LiteLLM: Arbitrary file deletion via `/audio/transcriptions`CVE-2024-4888 · LiteLLMHigh
- MLflow (REST API): DNS rebinding — no Origin header validationCVE-2025-14279 · MLflow (REST API)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.