CyberRota Analysis
AI-GeneratedSGLang is vulnerable to a model weight exfiltration attack when API keys are not configured, enabling remote attackers to exploit two exposed endpoints for distributed weight broadcasting via NCCL, leading to unauthorized data transfer. This vulnerability poses a significant risk as it allows attackers to exfiltrate sensitive model weights, potentially compromising the integrity of machine learning models. Organizations utilizing SGLang without proper API key configurations should prioritize addressing this vulnerability to safeguard their intellectual property and data.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL and then triggering data transfer, attackers can exfiltrate all model weights.
Related CVEs
Other vulnerabilities affecting the same vendor(s)