CVE-2026-27893: vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out
Two model implementation files hardcode trust_remote_code=True when loading sub-components, bypassing the user’s explicit --trust-remote-code=False security opt-out. This enables remote code execution via malicious model
repositories even when the user has explicitly disabled remote code trust.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-27893 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →