Impact
A flaw in the TiktokenTokenizer::new function of vllm-project vLLM allows a local attacker to manipulate the tiktoken vocabulary file and trigger a denial of service. The CVE description notes that the vulnerability results from improper handling and can be exploited only with local access, and the public exploit has already been released.
Affected Systems
vllm-project vLLM releases up to version 0.29.0 are impacted; no other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate impact potential, while the EPSS score of less than 1 % suggests a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local access to the system running vLLM and can be performed using the publicly available exploit; the pending pull request to fix the issue has not yet been merged.
OpenCVE Enrichment