A critical remote code execution vulnerability in the SGLang platform for multimodal AI models has been disclosed as CVE-2026-5760, with a CVSS 9.8 severity rating. The flaw affects the /v1/rerank endpoint and allows attackers to inject commands and execute arbitrary Python code in the context of the SGLang service by supplying a malicious tokenizer.chat_template during chat template rendering.
Public proof-of-concept exploit code is available, increasing the risk of active abuse before a vendor patch is released. According to the disclosure, the issue stems from use of an unsandboxed jinja2.Environment(), and CERT/CC has recommended replacing it with ImmutableSandboxedEnvironment as a mitigation until an updated SGLang version becomes available.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK reported that CVE-2026-5760 affects SGLang's /v1/rerank endpoint, enabling command injection and arbitrary Python code execution via a malicious tokenizer.chat_template rendered in an unsandboxed jinja2.Environment(). The advisory also noted that public proof-of-concept exploit code is available and relayed CERT-CC's mitigation to use ImmutableSandboxedEnvironment until a patched version is released.
A CVE record for CVE-2026-5760 was published, documenting a critical remote code execution vulnerability affecting SGLang.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.