Junglewise Threat Intelligence

CVE-2026-7302: SGLang path traversal in multimodal generation runtime

CVE-2026-7302 · Severity: critical · CVSS 9.1 · Published 2026-05-18

Technologies: SGLang Project SGLang, sglang (PyPI). Vendors: SGLang Project, PyPI.

Executive brief

SGLang is an open-source framework used to run and serve large AI models. A security flaw in its image and video processing component allows an unauthenticated attacker to upload malicious files to any location on the server's storage. This could allow an attacker to overwrite critical system files or gain full control over the server, potentially leading to data theft or service disruption.

Technical details

A path traversal vulnerability exists in SGLang's multimodal generation runtime within the _save_upload_to_path helper function. The application fails to sanitize the 'filename' parameter in multipart form uploads to the /v1/images/edits and /v1/videos endpoints, directly joining the user-supplied string with the uploads directory using os.path.join. An unauthenticated remote attacker can use '../' sequences to escape the intended directory and write arbitrary files anywhere the server process has write permissions. This can be leveraged to achieve remote code execution (RCE) by overwriting executable files or configuration scripts. As of the advisory date, no official patch is available; users are advised to restrict network access to SGLang interfaces.

Affected products

  • SGLang Project sglang >= 0.5.5, <= 0.5.12

Timeline

  • 2026-03-10: disclosed: Vulnerabilities reported to SGLang maintainers.
  • 2026-05-15: advisory: CERT/CC published Vulnerability Note VU#777338.
  • 2026-05-18: disclosed: CVE-2026-7302 published.

References

Related threats