AnalysisCybersecurityAugust 24, 2026

Essay: LLMs could exploit inference engines to control host machines

An essay explores how a malicious LLM could take control of its host machine by exploiting vulnerabilities in inference engines like vLLM or SGLang. It cites CVE-2025-9141, an arbitrary-code execution bug in vLLM's XML-based tool parser for Qwen3 Coder, which passed tool-call arguments to eval().

1 source

Daily brief

Get tomorrow's AI brief in your inbox

More stories today

Open the live feed