vLLM, an inference and serving engine for large language models, is vulnerable to arbitrary code execution during model resolution and initialization. Starting in version 0.10.1 and prior to 0.14.0, vLLM loads Hugging Face auto_map dynamic modules without properly gating that behavior on trust_remote_code. As a result, attacker-controlled Python code embedded in a model repository or local model path can be imported and executed when the server loads the model. The issue occurs during server startup/model load, before any request handling, and affects both remote Hugging Face repositories and local directories if an attacker can influence the selected model source.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
trust_remote_code semantics and review deployment pipelines to ensure only trusted model repositories and local model directories are referenced.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a small Python-only simulation of an AI model supply-chain RCE scenario labeled CVE-2026-22807. It contains: (1) vulnerable_lib.py implementing a toy model loader (MiniLLM) with a TOCTOU-style logic flaw—_resolve_model_class() dynamically imports a module specified by config.json:auto_map before enforcing trust_remote_code; (2) poc.py which builds a malicious model directory (dynamic_evil_model/) by writing a config.json that maps AutoModel to malicious.EvilModel and generating malicious.py whose top-level code runs os.system() with a user-supplied command (default whoami). When MiniLLM loads the model_path with trust_remote_code=False, the import executes the payload first, then the loader aborts—demonstrating code execution despite the later safety check. No network IOCs (URLs/IPs/domains) are present; the exploit is file-based and executes arbitrary local OS commands via Python import side effects.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.