CVE-2026-27893
HIGHvLLM's hardcoded trust_remote_code=True in NemotronVL and KimiK25 bypasses user security opt-out
Title source: cnaDescription
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the user's explicit `--trust-remote-code=False` security opt-out. This enables remote code execution via malicious model repositories even when the user has explicitly disabled remote code trust. Version 0.18.0 patches the issue.
References (17)
Core 17
Core References
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:10140
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:10141
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:19712
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:19724
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:19725
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:24977
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:8746
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:8747
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:8748
Vendor Advisory
https://access.redhat.com/security/cve/CVE-2026-27893
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2452055
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:37275
X_Refsource_Confirm x_refsource_confirm
https://github.com/vllm-project/vllm/security/advisories/GHSA-7972-pg2x-xr59
X_Refsource_Misc x_refsource_misc
https://github.com/vllm-project/vllm/pull/36192
X_Refsource_Misc x_refsource_misc
https://github.com/vllm-project/vllm/commit/00bd08edeee5dd4d4c13277c0114a464011acf72
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:42644
Scores
CVSS v3
8.8
EPSS
0.0135
EPSS Percentile
68.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-501
CWE-693
Status
published
Products (3)
pypi/vllm
0.10.1 - 0.18.0PyPI
vllm/vllm
0.10.1 - 0.18.0
vllm-project/vllm
>= 0.10.1, < 0.18.0
Published
Mar 27, 2026
Tracked Since
Mar 27, 2026