{"data":{"id":"4911c5f3-f942-4cf4-9d0b-6cf2b553f9bc","title":"CVE-2026-73560: vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in","summary":"vLLM, a system that runs large language models, has a security vulnerability before version 0.26.0 where the MiMoV2OmniMultiModalProcessor component improperly handles image and audio inputs by bypassing security checks (allowed_media_domains and allowed_local_media_path, which are supposed to restrict what files and websites the system can access). This flaw allows an attacker to trick the server into making requests or reading files that shouldn't be accessible.","solution":"Update vLLM to version 0.26.0 or later, which fixes this vulnerability.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73560","publishedAt":"2026-08-17T21:16:48.960Z","cveId":"CVE-2026-73560","cweIds":["CWE-918"],"cvssScore":"6.5","cvssSeverity":"medium","severity":"medium","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["HuggingFace"],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-17T21:16:48.960Z","capecIds":["CAPEC-664"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0010"]}}