Use of Less Trusted Source Affecting vllm package, versions [0.22.1,0.28.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.28% (19th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-VLLM-20158365
  • published27 Sept 2026
  • disclosed26 Sept 2026
  • creditrexpository

Introduced: 26 Sep 2026

NewCVE-2026-100653  (opens in a new tab)
CWE-348  (opens in a new tab)

How to fix?

Upgrade vllm to version 0.28.0 or higher.

Overview

vllm is an A high-throughput and memory-efficient inference and serving engine for LLMs

Affected versions of this package are vulnerable to Use of Less Trusted Source via incomplete propagation of revision and code_revision pins across artifact boundaries in the model loader subsystem. When an operator supplies a revision pin to lock a model to a specific version, several artifact-loading paths - including gguf_loader.py, kimi_audio.py, kimi_k25.py, registry.py, and roberta.py - ignore that pin and resolve config files, weight files, image processors, and sub-model artifacts against the default (latest) revision instead. An attacker who can influence the default-revision content of a Hugging Face repository can cause a pinned deployment to silently load unpinned, potentially malicious artifacts, achieving partial confidentiality impact and high integrity impact.

Note: This is only exploitable when an operator supplies a revision or code_revision pin and the attacker can influence the content served at the unpinned (default) revision of the target repository.

References

CVSS Base Scores

version 4.0
version 3.1