CVE-2025-66448 | vLLM up to 0.11.0 get_class_from_dynamic_module code injection (GHSA-8fr4-5q9j-m8gm)
A vulnerability was found in vLLM up to 0.11.0 and classified as critical. Affected by this vulnerability is the function get_class_from_dynamic_module. The manipulation results in code injection.
This vulnerability is known as CVE-2025-66448. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.