CVE-2026-90553 | vllm-project vLLM up to 0.27.x LlavaOnevision2 processor loader processing_llava_onevision2.py trust_remote_code code injection

SecurityVulns

A vulnerability described as critical has been identified in vllm-project vLLM up to 0.27.x. This vulnerability affects unknown code of the file processing_llava_onevision2.py of the component LlavaOnevision2 processor loader. Such manipulation of the argument trust_remote_code leads to code injection.

This vulnerability is uniquely identified as CVE-2026-90553. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More