Arbitrary Code Execution Vulnerability in SGLang's Multimodal Generation Runtime
CVE-2026-93088
Currently unrated
What is CVE-2026-93088?
The SGLang multimodal generation runtime is exposed to arbitrary code execution through its disaggregated-diffusion orchestrator, which binds an unauthenticated ZeroMQ ROUTER socket to a network interface. This flaw allows an attacker to exploit the system by sending multipart messages that are processed without any validation, leading to unsafe operations with pickle.loads(). As a result, unauthorized users can execute code remotely, posing serious security risks to the integrity and confidentiality of the system.
Affected Version(s)
SGLang 0.5.11 <= 0.5.14
