Executive brief
vLLM, a library used for serving and deploying large language models, is vulnerable to a security flaw that allows for remote code execution. An attacker can create a malicious model configuration that, when loaded by a user or automated system, silently executes arbitrary code on the host machine. This occurs even if the user has explicitly disabled the setting to trust remote code, potentially leading to full system compromise or data theft.
Technical details
A remote code execution (RCE) vulnerability exists in vLLM's 'Nemotron_Nano_VL_Config' class within 'transformers_utils/get_config'. The vulnerability is caused by the improper handling of 'auto_map' entries in model configurations, which are resolved using 'get_class_from_dynamic_module' and immediately instantiated. This process fetches and executes Python code from remote repositories without enforcing the 'trust_remote_code' safety flag. An attacker can exploit this by providing a malicious model configuration that points to a remote repository containing arbitrary code. The vulnerability is patched in version 0.11.1.
Affected products
- vllm-project vllm < 0.11.1
Timeline
- 2025-12-01: advisory: NVD publication date
- 2025-12-02: disclosed: GitHub Advisory published
- 2025-12-02: patched: GitHub Advisory marked as reviewed and patched version identified