Arbitrary Code Execution Vulnerability in SGLang's Multimodal Generation Runtime
CVE-2026-93088

Currently unrated

Key Information:

Vendor

Sglang

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-93088?

The SGLang multimodal generation runtime is exposed to arbitrary code execution through its disaggregated-diffusion orchestrator, which binds an unauthenticated ZeroMQ ROUTER socket to a network interface. This flaw allows an attacker to exploit the system by sending multipart messages that are processed without any validation, leading to unsafe operations with pickle.loads(). As a result, unauthorized users can execute code remotely, posing serious security risks to the integrity and confidentiality of the system.

Affected Version(s)

SGLang 0.5.11 <= 0.5.14

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.