Best AI News — Updated Every 3 Hours
Story Page
← All Stories
Home Community Story
Community

vLLM CVE-2026-27893, `--trust-remote-code=False` is silently ignored for Nemotron-VL and Kimi-K25 models

Via r/LocalLlama
Sunday, Mar 29, 2026 · 6:32PM
Summary

Two vLLM model files hardcode `trust_remote_code=True`, overriding an explicit `False` setting with no warning or log entry. A malicious Hugging Face repository targeting either architecture can achieve code execution on the inference server. This is the third time the same vulnerability class has s

Continue reading the full article
Read at r/LocalLlama
www.reddit.com
Back to all stories