// AI threat desk · 30 Sept 2026
Sample content · apart from the Arup deepfake case, every company, product and CVE ID is fictional
Home/CVE · Vulns & Patches
Vulns & PatchesHighPATCHCVSS 8.8

Two exploited Vellum Serve flaws allow remote code execution

Vellum Serve's model upload endpoint skips authentication, so an attacker can upload a crafted config file and run code on the server. The maintainers say attacks are under way and urge users to move to 2.11.0.

A server aisle in a data centre
File photo: A server aisle in a data centre. Photo: rawpixel (CC0)

Vellum Serve's model upload endpoint skips authentication, so an attacker can upload a crafted config file and run code on the server. The maintainers say attacks are under way and urge users to move to 2.11.0.

Sample content: on the live site this story follows the same structure, with what happened, who is affected, what to do, an FAQ and sources.

Explore with AI