SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.
{
"cwe_ids": [
"CWE-35"
],
"github_reviewed": true,
"github_reviewed_at": "2026-05-29T17:26:20Z",
"nvd_published_at": "2026-05-18T12:16:16Z",
"severity": "CRITICAL"
}