VDB

CVE-2026-7302

CVE-2026-7302 PUBLISHED CVSS 8.5 HIGH

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.

EPSS 0.10% · 27.2th percentile

Risk Scores

CVSS 4.0
8.5
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.10%
27.2th percentile

Affected Products

VendorProductVersions
SGLangSGLang5.10

Timeline

  • May 18, 2026 CVE Published
  • May 18, 2026 Security Advisory
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
  • May 26, 2026 EPSS Score
  • May 27, 2026 EPSS Score
  • May 28, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›