0.5.13
2 years ago
1 days ago
Known vulnerabilities in the sglang package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
sglang is a SGLang is a fast serving framework for large language models and vision language models. Affected versions of this package are vulnerable to Deserialization of Untrusted Data in the Note: This is only exploitable if multimodal runtime is enabled and the scheduler socket is reachable ( How to fix Deserialization of Untrusted Data? There is no fixed version for | [0.5.5,) |
sglang is a SGLang is a fast serving framework for large language models and vision language models. Affected versions of this package are vulnerable to Directory Traversal via the upload filename parameter in specific endpoints. An unauthenticated attacker can overwrite or create arbitrary files on the server by including directory traversal sequences in the filename. Note: This is only exploitable if multimodal runtime is enabled. How to fix Directory Traversal? There is no fixed version for | [0.5.5,) |
sglang is a SGLang is a fast serving framework for large language models and vision language models. Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the Note: This is only exploitable if the How to fix Deserialization of Untrusted Data? There is no fixed version for | [0.4.1.post7,) |
sglang is a SGLang is a fast serving framework for large language models and vision language models. Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via the How to fix Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')? There is no fixed version for | [0.5.10rc0,) |