CVE-2026-7302
CVE-2026-7302
CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th
SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.
| Vendor | sglang |
| Product | sglang |
| Published | May 18, 2026 |
| Last Updated | May 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for sglang sglang
Be the first to know when new critical vulnerabilities affecting sglang sglang are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
SGLang / SGLang
5.10