PulseAugur
中
实时 22:15:41
English(EN) CERT/CC issued advisory VU#915947 for SGLang (an AI inference server), CVE-2026-5760, severity 9.8. A poisoned GGUF model file carries a chat-template that SGLa

SGLang AI推理服务器遭遇关键漏洞CVE-2026-5760

SGLang,一个AI推理服务器,被发现存在一个严重性评分为9.8的关键安全漏洞(CVE-2026-5760)。该问题源于一个被投毒的GGUF模型文件,其中包含一个chat-template,SGLang通过未沙箱化的Jinja2处理该模板,从而允许在主机系统上执行任意Python代码。此漏洞与之前在llama-cpp-python和vLLM中发现的问题类似,突显了在多个AI框架中处理模型文件模板方面存在的持续性疏忽。 AI

影响 SGLang中的关键漏洞允许任意代码执行,影响AI模型部署的安全性。

排序理由 针对开源AI推理服务器的安全公告,具有关键严重性评分。

在 Mastodon — fosstodon.org 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

SGLang AI推理服务器遭遇关键漏洞CVE-2026-5760

本文如何被排名

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Research
针对开源AI推理服务器的安全公告,具有关键严重性评分。
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
safety, infra
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
162 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.

完整方法见我们的编辑标准。

报道来源 [1]

  1. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    CERT/CC 发布了针对 SGLang(一个AI推理服务器)的公告VU#915947,CVE-2026-5760,严重性9.8。一个被投毒的GGUF模型文件包含一个SGLa的聊天模板

    CERT/CC issued advisory VU#915947 for SGLang (an AI inference server), CVE-2026-5760, severity 9.8. A poisoned GGUF model file carries a chat-template that SGLang renders through Jinja2 with no sandbox. Arbitrary Python runs on the host. Same root cause as llama-cpp-python (2024)…