Pickle in the Pipeline: Critical RCE Vulnerabilities in SGLang’s LLM Serving Framework
Table of contentsQuick OverviewCVSS RationaleWhat Is SGLang?Technical AnalysisRoot Cause: Python's pickle on Untrusted Network DataHow Pickle Deserialization Becomes Code ExecutionProposed...