CVE-2026-100653: vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagation
vLLM is an inference and serving engine for large language models. In versions from 0.22.1 through 0.28.0, the operator-supplied model revision pin (--revision / --code-revision) is not propagated to several Hugging Face artifact loads for the FunAudioChat and Tarsier2 architectures: the WhisperFeatureExtractor and speechtokenizer PreTrainedTokenizerFast loads in vllm/modelexecutor/models/funaudiochat.py and the Qwen2VLConfig.frompretrained call used by Tarsier2ProcessingInfo in vllm/modelexecutor/models/qwen2vl.py. As a result, deployments pinned to a reviewed revision still resolve these behavior-affecting processor, tokenizer, and config artifacts from the repository's default revision, so a later change to the upstream default branch can alter audio preprocessing, speech tokenizer behavior, or Tarsier2 configuration without any change to the operator's configured pin. This is a supply-chain integrity and reproducibility failure for pinned deployments; it is residual to the earlier fix tracked as GHSA-3ww4-5jv9-j5gm / CVE-2026-47155 and does not constitute remote code execution or a trustremotecode=False bypass. The issue is fixed in version 0.28.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vLLMto a version that resolves this vulnerability.Fixed in 0.28.0
Event History
Frequently Asked Questions
Which deployments are affected?
Affected deployments use vLLM versions from 0.22.1 through 0.28.0 and load the FunAudioChat or Tarsier2 architectures. The issue matters when an operator supplies a model revision pin with --revision or --code-revision and expects all related artifacts to use that reviewed revision.
What would need to happen for this issue to have an effect?
A behavior-affecting processor, tokenizer, or configuration artifact on the upstream repository's default revision would need to change after the operator selected their pin. The unpinned loads can then resolve that default-revision artifact despite the configured model revision pin.
Does this allow remote code execution or bypass trust_remote_code=False?
No. The issue is described as a supply-chain integrity and reproducibility failure and does not constitute remote code execution or a trust_remote_code=False bypass.
What is the remediation?
Upgrade to vLLM 0.28.0, which fixes the incomplete artifact-pin propagation. Until then, deployments relying on reviewed revision pins should recognize that the affected FunAudioChat and Tarsier2 artifact loads may still follow the upstream default revision.