{"id":"CVE-2026-93088","published":"2026-09-22T15:17:21.433","lastModified":"2026-09-22T19:16:57.450","description":"SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and passes the final frame of received multipart messages directly to pickle.loads() before any validation occurs.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-502"],"vendors":[],"products":[],"references":[{"url":"https://github.com/sgl-project/sglang/blob/main/python/sglang/multimodal_gen/runtime/disaggregation/orchestrator.py","tags":[]},{"url":"https://hacchoomiso.github.io/blog/SGLang/CVE-2026-93088/","tags":[]},{"url":"https://hacchoomiso.github.io/blog/SGLang/CVE-2026-93088/","tags":[]}],"exploitRefs":[{"url":"https://github.com/sgl-project/sglang/blob/main/python/sglang/multimodal_gen/runtime/disaggregation/orchestrator.py","tags":[]}],"hasPoc":true,"ai":{"summary":"The vulnerability allows unauthenticated attackers to execute arbitrary code by exploiting the unvalidated handling of multipart messages in the DiffusionServer.","exploitability":"Exploitation is relatively straightforward given the unauthenticated nature and direct deserialization of received messages.","blast_radius":"If exploited, this could lead to complete compromise of the affected system, potentially allowing attackers to gain full control over the server.","remediation":"Disable the affected feature or restrict access to the DiffusionServer endpoint.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","unauth","code-execution"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:49:38.096Z"}}