You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: advisories/github-reviewed/2025/09/GHSA-9w53-xr52-mwgj/GHSA-9w53-xr52-mwgj.json
+39-6Lines changed: 39 additions & 6 deletions
Original file line number
Diff line number
Diff line change
@@ -1,11 +1,12 @@
1
1
{
2
2
"schema_version": "1.4.0",
3
3
"id": "GHSA-9w53-xr52-mwgj",
4
-
"modified": "2025-09-09T21:30:26Z",
4
+
"modified": "2025-10-29T16:00:06Z",
5
5
"published": "2025-09-09T21:30:26Z",
6
6
"aliases": [
7
7
"CVE-2025-10164"
8
8
],
9
+
"summary": "SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor",
9
10
"details": "A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.",
0 commit comments