Vulnerability Description
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the device running the script.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lmsys | Sglang | < 0.5.10 |
Related Weaknesses (CWE)
References
- https://github.com/sgl-project/sglang/blob/main/scripts/playground/replay_requesProduct
- https://github.com/sgl-project/sglang/pull/20904Issue TrackingPatch
- https://github.com/sgl-project/sglang/releases/tag/v0.5.10Release Notes
- https://orca.security/resources/blog/sglang-llm-framework-rce-vulnerabilities/ExploitThird Party Advisory
FAQ
What is CVE-2026-3989?
CVE-2026-3989 is a vulnerability with a CVSS score of 7.8 (HIGH). SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will...
How severe is CVE-2026-3989?
CVE-2026-3989 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-3989?
Check the references section above for vendor advisories and patch information. Affected products include: Lmsys Sglang.