CVE-2026-7302 PUBLISHED

CVE-2026-7302

Assigner: certcc
Reserved: 28.04.2026 Published: 18.05.2026 Updated: 18.05.2026

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.

Product Status

Vendor SGLang
Product SGLang
Versions
  • Version 5.10 is affected

References

Problem Types

  • CWE-35: Path Traversal: '.../...//'