vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning controls do not consisten
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
계획된 패치 주기 내 조치(60일 이내)
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N약점 (CWE)
상세 설명
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning controls do not consistently apply to all artifacts loaded for a model. A deployment that supplies --revision or --code-revision can still load dynamic code, GGUF files, image processors, retrieval side weights, or same-repository subfolder weights/config from an unpinned/default revision. This is a supply-chain integrity issue for pinned vLLM deployments. Operators can believe they are serving a reviewed model revision while vLLM resolves behavior-affecting nested or sibling artifacts outside that reviewed revision. This vulnerability is fixed in 0.22.0.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- vllm vllm< 0.22.0other
영향받는 구성 (CPE) 1
- vllm vllm< 0.22.0cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*
참고 자료 4
- https://github.com/vllm-project/vllm/pull/42616Issue Tracking
- https://github.com/vllm-project/vllm/security/advisories/GHSA-3ww4-5jv9-j5gmThird Party Advisory
- https://huntr.com/bounties/3f1e24c0-87d2-4f6c-a705-820f380879acThird Party Advisory
링크 내용 불러오는 중…