PT-2026-93819 · Lmdeploy · Lmdeploy
CVE-2025-59953
·
Published
2026-09-16
·
Updated
2026-09-18
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LMDeploy versions 0.9.1 through 0.10.1
Description
LMDeploy implements an RPC server via
AsyncRPCServer in zmq rpc.py to support RPC communications. The call and response() function uses pickle.loads() to deserialize received messages without proper sanitization. This allows a remote attacker to send malicious pickle data to the RPC address, leading to remote code execution on the victim's machine. The RPC server previously bound to tcp://*, which exposed the service to the network on a randomly selected port.Recommendations
Update to version 0.10.2.
Enable authentication in RPC services to ensure only trusted users can join the cluster.
As a temporary mitigation, restrict access to the RPC server to localhost to remove the remote network attack surface.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lmdeploy