Junglewise Threat Intelligence

CVE-2025-66448: vLLM remote code execution in Nemotron_Nano_VL_Config via auto_map

CVE-2025-66448 · Severity: high · CVSS 7.1 · Published 2025-12-02

Technologies: vllm (PyPI), vLLM Project vllm. Vendors: PyPI, vLLM Project.

Executive brief

vLLM, a library used for serving and deploying large language models, is vulnerable to a security flaw that allows for remote code execution. An attacker can create a malicious model configuration that, when loaded by a user or automated system, silently executes arbitrary code on the host machine. This occurs even if the user has explicitly disabled the setting to trust remote code, potentially leading to full system compromise or data theft.

Technical details

A remote code execution (RCE) vulnerability exists in vLLM's 'Nemotron_Nano_VL_Config' class within 'transformers_utils/get_config'. The vulnerability is caused by the improper handling of 'auto_map' entries in model configurations, which are resolved using 'get_class_from_dynamic_module' and immediately instantiated. This process fetches and executes Python code from remote repositories without enforcing the 'trust_remote_code' safety flag. An attacker can exploit this by providing a malicious model configuration that points to a remote repository containing arbitrary code. The vulnerability is patched in version 0.11.1.

Affected products

  • vllm-project vllm < 0.11.1

Timeline

  • 2025-12-01: advisory: NVD publication date
  • 2025-12-02: disclosed: GitHub Advisory published
  • 2025-12-02: patched: GitHub Advisory marked as reviewed and patched version identified

References

Related threats