lmsys sglang processes network-supplied data in the main function of /update_weights_from_tensor. Manipulating the serialized_named_tensors argument causes the input to enter a deserialization path without sufficient validation that the resulting data is valid. At a high level, a remote attacker can submit specially crafted input to the affected processing path; the record states that exploitation does not require authentication and the supplied vector indicates no user interaction. The weakness is classified as CWE-502, with CWE-20 identifying improper input validation as a related weakness. The specific serialization format, payload structure, and deployment conditions required for the final impact have not been fully disclosed.