PT-2026-93819 · Lmdeploy · Lmdeploy

CVE-2025-59953

·

Published

2026-09-16

·

Updated

2026-09-18

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LMDeploy versions 0.9.1 through 0.10.1
Description LMDeploy implements an RPC server via AsyncRPCServer in zmq rpc.py to support RPC communications. The call and response() function uses pickle.loads() to deserialize received messages without proper sanitization. This allows a remote attacker to send malicious pickle data to the RPC address, leading to remote code execution on the victim's machine. The RPC server previously bound to tcp://*, which exposed the service to the network on a randomly selected port.
Recommendations Update to version 0.10.2. Enable authentication in RPC services to ensure only trusted users can join the cluster. As a temporary mitigation, restrict access to the RPC server to localhost to remove the remote network attack surface.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-59953
GHSA-5H8J-6CRG-7RMW

Affected Products

Lmdeploy