AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

GHSA-7972-pg2x-xr59: vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out

OSV AI package advisories · observation · Mar 27, 2026 · UTC

### Summary Two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the user's explicit `--trust-remote-code=False` security opt-out. This enables remote code execution via malicious model repositories even when the user has explicitly disabled remote code trust. ### Details **Affected files (latest main branch):** 1. `vllm/model_executor/models/nemotron_vl.py:430` ```python vision_model = AutoModel.from_config(config.vision_config, trust_remote_code=True) ``` 2. vllm/model_executor/models/kimi_k25.py:177 ```python cached_get_image_processor(self

Read original source ↗ Open in workspace

recordType
vulnerability
status
active
evidenceStatus
reported
region
Global

Evidence & attribution

First collected: 2026-09-20T22:31:48.298Z. This is not the publication date.