PT-2026-99324 · Vllm · Vllm
CVSS v4.0
8.3
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
vLLM versions 0.22.1 through 0.27.9
Description
A supply-chain integrity and reproducibility issue exists where the model revision pin provided via
--revision or --code-revision is not propagated to specific Hugging Face artifact loads for FunAudioChat and Tarsier2 architectures. Specifically, this affects the WhisperFeatureExtractor and speech tokenizer PreTrainedTokenizerFast loads in vllm/model executor/models/funaudiochat.py, as well as the Qwen2VLConfig.from pretrained() function used by Tarsier2ProcessingInfo in vllm/model executor/models/qwen2 vl.py. Consequently, deployments pinned to a specific revision may still load processor, tokenizer, and configuration artifacts from the repository's default revision, allowing upstream changes to the default branch to alter audio preprocessing, speech tokenizer behavior, or Tarsier2 configuration without the operator's knowledge.Recommendations
Update vLLM to version 0.28.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vllm