CVE-2026-7669 is a remote code-injection vulnerability in sgl-project SGLang through 0.5.9 in the HuggingFace Transformer Handler's tokenizer-loading logic. When a caller explicitly supplies trust_remote_code=False, the get_tokenizer function may silently retry loading the tokenizer with trust_remote_code=True after HuggingFace Transformers v5 returns a TokenizersBackend fallback for an unregistered tokenizer class. This overrides the caller's security choice without warning. A model repository that declares a remotely loadable custom tokenizer can consequently cause arbitrary Python code to execute in the SGLang process. Both auto and slow tokenizer modes are affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a real PoC exploit for CVE-2026-7669, targeting SGLang’s tokenizer-loading logic. The core claim is that SGLang silently overrides trust_remote_code=False to True when transformers 5.x returns a TokenizersBackend, causing a second AutoTokenizer.from_pretrained call that executes attacker-supplied tokenizer.py code. Repository structure: the top-level PoC logic is in run_poc.py, setup_model.py, run.sh, entrypoint.sh, Dockerfile, Dockerfile.versions, pinned_versions.json, and README.md. setup_model.py builds a crafted local Hugging Face-style model directory under /poc/malicious_model containing config.json, tokenizer_config.json, tokenizer.json, model.safetensors, and a malicious tokenizer.py. run_poc.py performs preflight pin verification, executes multiple phases to distinguish benign transformers behavior from vulnerable SGLang behavior, writes a claim ledger, and exits with status codes indicating confirmed/not triggered/false positive/version drift. run.sh wraps Docker build/run flows and supports normal execution, server-path testing, version matrix testing, ledger export, and an opt-in reverse shell mode. Exploit capability: arbitrary Python execution inside the SGLang process when an operator loads an attacker-controlled model path while expecting trust_remote_code=False to prevent code execution. The payload is operational rather than merely demonstrative: it writes a proof file, captures selected environment variables and runtime metadata, reads /etc/passwd excerpts, checks device files, runs ip addr, and optionally opens a reverse shell to ATTACKER_HOST:4444 using /bin/sh -i. Attack path: attacker supplies a malicious model/tokenizer layout using tokenizer_class plus auto_map pointing to tokenizer.MaliciousTokenizer. The first tokenizer load yields TokenizersBackend; vulnerable SGLang then retries with trust_remote_code=True, importing tokenizer.py and executing top-level attacker code. The PoC includes control phases to show transformers alone does not execute the payload under the same conditions, and a patched-SGLang phase to isolate the vulnerable retry block. The bundled sglang_source/ tree is mostly upstream source included to pin and reproduce the vulnerable environment; it is not itself the exploit payload. It also contains many unrelated benchmark/eval utilities with additional URLs and local API endpoints, but the exploit-relevant files are the top-level PoC scripts and the crafted malicious model artifacts they generate.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.