CVE-2026-22807 | vLLM up to 0.13.x Hugging Face auto_map code injection (GHSA-2pc9-4j83-qjmr / EUVD-2026-3678)
A vulnerability identified as critical has been detected in vLLM up to 0.13.x. This issue affects the function auto_map of the component Hugging Face. Performing a manipulation results in code injection.
This vulnerability is known as CVE-2026-22807. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.