CVE-2025-66448·Python vulnerability
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote code execution vector in a config class named Nemotron_Nano_VL_Config. When vllm loads a model config that contains an auto_map entry, the config class resolves that mapping with get_class_from_dynamic_module(...) and immediately instantiates the returned class. This fetches and executes Python from the remote repository referenced in the auto_map string. Crucially, this happens even when the caller explicitly sets trust_remote_code=False in vllm.transformers_utils.config.get_config. In practice, an attacker can publish a benign-looking frontend repo whose config.json points via auto_map to a separate malicious backend repo; loading the frontend will silently run the backend’s code on the victim host. This vulnerability is fixed in 0.11.1.
- Severity
- high
- Software
- Python
- Fixed in
- 0.11.1
- Published
- 2025-12-01
Affected versions
Until: 0.11.1
Fixed in: 0.11.1
How to fix this CVE
Update vLLM to version 0.11.1 or later to fix a critical remote code execution vulnerability that bypasses trust_remote_code=False settings. This flaw allows arbitrary Python code execution when loading model configurations with auto_map entries pointing to external repositories. Immediately patch all systems running vLLM versions prior to 0.11.1, especially those exposed to untrusted model sources.
sudo dnf update python3-vllm || pip3 install --upgrade 'vllm>=0.11.1'Defensia detects this vulnerability
How to check if you are affected
- Run 'pip3 show vllm | grep Version' to confirm the installed vLLM version and verify if it is below 0.11.1
- Check your vLLM configuration files and model directories for auto_map entries in config.json files that reference external repositories
- Search application logs for unexpected Python module imports or dynamic class instantiations occurring after model loading, particularly patterns like 'get_class_from_dynamic_module' or 'from_pretrained' operations
- Verify the fix by running 'pip3 show vllm' again and confirming the version is 0.11.1 or higher, then restart all vLLM services and test model loading with trust_remote_code=False explicitly set
FAQ
What is CVE-2025-66448?
CVE-2025-66448 is a remote code execution vulnerability in vLLM that allows attackers to execute arbitrary Python code by crafting malicious model configurations with auto_map entries pointing to external repositories. The flaw persists even when trust_remote_code=False is explicitly set, making it particularly dangerous for users who believe they are loading models safely.
Is CVE-2025-66448 being actively exploited?
No, CVE-2025-66448 is not currently listed on the CISA Known Exploited Vulnerabilities catalog and no public exploits are available. However, the vulnerability is trivial to exploit and organizations should patch immediately as a precautionary measure.
What versions of vLLM are affected by CVE-2025-66448?
All vLLM versions prior to 0.11.1 are affected. The vulnerability exists in the Nemotron_Nano_VL_Config class and its config loading mechanism, which was present in all earlier releases.
How do I check if my server is vulnerable to CVE-2025-66448?
Run 'pip3 show vllm | grep Version' and check if the version is below 0.11.1. If it is, your installation is vulnerable and requires immediate patching.
Does Defensia detect CVE-2025-66448?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If vLLM is installed on a monitored server, CVE-2025-66448 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-66448. Free for 1 server.
Get started free