CVE-2026-7302
SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2026-7302, https://antiproof.ai/blog/three-rces-in-sglang, https://github.com/sgl-project/sglang, https://github.com/sgl-project/sglang/tree/main/python/sglang
