Lmsys
15 known vulnerabilities
Top Products
SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two end
SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyf
SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically wi
SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitize
SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when D
SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denyl
SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that d
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_h
SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-lo
SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an atta
SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that cal
SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious to
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An at
SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disagg
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, whi
Frequently Asked Questions
How many CVEs affect Lmsys?
Lmsys has 15 CVE records in our database, including 10 critical and 3 high severity vulnerabilities.
What are the most severe Lmsys vulnerabilities?
Lmsys has 10 critical severity (CVSS 9.0+) and 3 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Lmsys vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Lmsys products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Lmsys Vulnerabilities
CyberStrike scans your infrastructure for Lmsys vulnerabilities and provides real-time remediation guidance.
Get Started