Executive brief
SGLang is an open-source framework for deploying large language models. The /update_weights_from_tensor endpoint allows unauthenticated attackers to send crafted pickle-serialized data when no API keys are configured. By exploiting bypasses in the SafeUnpickler safety mechanism, an attacker can execute arbitrary code on the SGLang server, potentially compromising all models and data processed by it.
Technical details
The vulnerability is a pickle deserialization attack (CWE-502) in SGLang's SafeUnpickler implementation. The SafeUnpickler was introduced to mitigate CVE-2025-10164 but has flawed logic: its allowlist includes the broad "builtins." prefix, and its denylist omits __import__ and getattr. An attacker can chain these permitted builtins functions to construct a gadget chain that reaches os.system or other dangerous functions. The /update_weights_from_tensor endpoint at the HTTP server (python/sglang/srt/entrypoints/http_server.py) accepts base64-encoded pickle payloads with AuthLevel.ADMIN_OPTIONAL, making it unauthenticated when no keys are configured. When the payload is deserialized, the GLOBAL pickle opcode triggers find_class(), which fails to block the __import__/__getattr__ gadget chain, leading to remote code execution.
Affected products
- SGLang SGLang
Timeline
- 2026-09-11: disclosed