Back to CVE List

CVE-2026-3989

HIGH SEVERITY

CVSS Score & Metrics

Base Score
7.8 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Vulnerability Description

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the device running the script.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
pip
Product
sglang

External References

Discussion (0)

Add Comment

No comments yet. Be the first!