Executive brief
vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder
Affected products
- PyPI vllm
Junglewise Threat Intelligence
CVE-2025-9141 · Severity: low · CVSS 3.1 · Published 2026-07-07
Technologies: vllm (PyPI). Vendors: PyPI.
vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder