SOURCE-LINKED INTELLIGENCE
GHSA-6c4r-fmh3-7rh8: vLLM: Processing differential in multi-channel audio downmixing enables hidden-input/moderation bypass for audio models
## Issue Description Librosa defaults to using `numpy.mean` for mono downmixing (`to_mono`), while the international standard ITU-R BS.775-4 specifies a weighted downmixing algorithm. This discrepancy results in: - Inconsistency between audio heard by humans (e.g., through headphones/regular speakers) and audio processed by AI models (Which infra via Librosa, such as vllm, transformer). https://github.com/librosa/librosa/blob/af8c839fb15317fa2712ea66e7a22da6a9267b32/librosa/core/audio.py#L478 ## Attack Scenario and Impact ### LFE (Low-Frequency Effects) Channel Exploit Attackers can craft spec
Read original source ↗ Open in workspace
- recordType
- vulnerability
- status
- active
- evidenceStatus
- reported
- region
- Global
Evidence & attribution
- OSV AI package advisories · 2026-07-17T16:52:53.000Z
- OSV AI package advisories · 2026-04-02T20:16:25.437Z
First collected: 2026-09-20T22:31:48.298Z. This is not the publication date.