CVE-2026-5760 is a critical server-side template injection vulnerability in SGLang's reranking functionality. SGLang renders a model-supplied tokenizer.chat_template using an unsandboxed Jinja2 Environment rather than ImmutableSandboxedEnvironment. A crafted template embedded in a malicious GGUF model can escape the template context and cause arbitrary Python code and operating-system commands to execute when SGLang renders the template during reranking.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact proof-of-concept exploit for CVE-2026-5760 affecting SGLang. It contains two files: a README describing the vulnerability and exploitation flow, and a single Python script (exploit.py) that serves as the main entry point. The exploit targets SGLang's reranking functionality, specifically the /v1/rerank path, where model-supplied chat templates are rendered with jinja2.Environment() instead of a sandboxed environment. The Python script has two main capabilities: (1) it generates a malicious GGUF model file named malicious_reranker.gguf with a crafted tokenizer chat template, and (2) it locally reproduces the vulnerable rendering behavior by instantiating an unsandboxed Jinja2 environment and rendering the payload directly. The embedded payload uses lipsum.__globals__["os"].popen(cmd).read() to execute arbitrary shell commands and return their output. The exploit is operational rather than just theoretical because it includes a working payload and artifact generation, but it is not framework-based or heavily weaponized. There are no hardcoded external IPs or domains; the key fingerprintable target is the vulnerable HTTP endpoint /v1/rerank and the malicious GGUF artifact used to deliver the payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical remote code execution vulnerability in the SGLang inference server caused by unsandboxed Jinja2 template rendering in the reranking endpoint, allowing malicious GGUF model metadata to execute arbitrary code on the host.
Critical remote code execution vulnerability in the SGLang platform's /v1/rerank endpoint caused by unsafe rendering of malicious chat templates via an unsandboxed jinja2.Environment(), allowing arbitrary embedded Python code execution in the SGLang service context.
A critical remote code execution vulnerability in SGLang's /v1/rerank endpoint caused by unsafe Jinja2 template rendering of a malicious GGUF model file.
A remote code execution vulnerability in SGLang's /v1/rerank endpoint caused by rendering a malicious tokenizer.chat_template with an unsandboxed Jinja2 environment.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.