Database/AI/ML frameworks & serving

SGLang (`/v1/rerank`): RCE via a malicious `tokenizer.chat_template` rendered as Jinja2
CVE-2026-5760AI/ML frameworks & servingcurated
Impact
RCE via a malicious tokenizer.chat_template rendered as Jinja2
Who can reach it
Customer-supplied model file — the chat template inside the model repo is the payload
What to do
Upgrade. Jinja chat templates are code; scanning the weights does not cover the tokenizer config
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.