CVE-2026-7302
EUVD-2026-3076418.05.2026, 12:16
SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lmsys | sglang | 0.5.10 |
𝑥
= Vulnerable software versions