A recent report highlights six critical vulnerabilities in SGLang, a framework using large language models. Three of these vulnerabilities allow unauthenticated remote code execution (RCE), with the most severe having a CVSS score of 9.8. No patches are available yet, and exploitation does not require authentication, posing significant risks to exposed systems.
There are currently no confirmed cases of in-the-wild exploitation, but researchers warn that technical details are public, increasing potential vulnerability. Recommendations include restricting access to the service and applying security updates.