{"id":"GHSA-7972-pg2x-xr59","summary":"vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out","details":"### Summary\n\n  Two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the user's explicit `--trust-remote-code=False` security opt-out. This enables remote code execution via malicious model\n  repositories even when the user has explicitly disabled remote code trust.\n\n  ### Details\n\n  **Affected files (latest main branch):**\n\n  1. `vllm/model_executor/models/nemotron_vl.py:430`\n  ```python\n  vision_model = AutoModel.from_config(config.vision_config, trust_remote_code=True)\n```\n\n  2. vllm/model_executor/models/kimi_k25.py:177\n \n```python\n  cached_get_image_processor(self.ctx.model_config.model, trust_remote_code=True)\n```\n\n  Both pass a hardcoded trust_remote_code=True to HuggingFace API calls, overriding the user's global --trust-remote-code=False setting.\n\n  Relation to prior CVEs:\n  - CVE-2025-66448 fixed auto_map resolution in vllm/transformers_utils/config.py (config loading path)\n  - CVE-2026-22807 fixed broader auto_map at startup\n  - Both fixes are present in the current code. These hardcoded instances in model files survived both patches — different code paths.\n\n### Impact\n\n  Remote code execution. An attacker can craft a malicious model repository that executes arbitrary Python code when loaded by vLLM, even when the user has explicitly set --trust-remote-code=False. This undermines the security guarantee\n  that trust_remote_code=False is intended to provide.\n\n  Remediation: Replace hardcoded trust_remote_code=True with self.config.model_config.trust_remote_code in both files. Raise a clear error if the model component requires remote code but the user hasn't opted in.","aliases":["CVE-2026-27893","PYSEC-2026-2297"],"modified":"2026-09-10T03:50:37.897591835Z","published":"2026-03-27T15:27:20Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-03-27T15:27:20Z","nvd_published_at":"2026-03-27T00:16:22Z","cwe_ids":["CWE-693"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-7972-pg2x-xr59"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27893"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/36192"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/00bd08edeee5dd4d4c13277c0114a464011acf72"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27893.json"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2297.yaml"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2452055"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-27893"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:8748"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:8747"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:8746"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:24977"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:19725"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:19724"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:19712"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:10141"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:10140"}],"affected":[{"package":{"name":"vllm","ecosystem":"PyPI","purl":"pkg:pypi/vllm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.10.1"},{"fixed":"0.18.0"}]}],"versions":["0.10.1","0.10.1.1","0.10.2","0.11.0","0.11.1","0.11.2","0.12.0","0.13.0","0.14.0","0.14.1","0.15.0","0.15.1","0.16.0","0.17.0","0.17.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-7972-pg2x-xr59/GHSA-7972-pg2x-xr59.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}