vllm is vulnerable to Information Disclosure
33
Low Risk
Malformed requests raise a validation error that is converted to a string including the handler's internal file path and line number. The sanitizer strips memory addresses but not file/line patterns, so the response leaks the operating-system username, home and virtual-environment paths, Python version, and internal module structure. An unauthenticated client can extract this with a single malformed request to any JSON POST endpoint. The fix builds the error message from structured fields instead of the raw exception string.
You are affected if you are using a version that falls within the vulnerable range.
vllm is vulnerable to Information Disclosure in versions 0.0.1 - 0.25.1.
Upgrade the vllm library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant