PT-2026-95544 · Lmdeploy · Lmdeploy
CVE-2025-66455
·
Published
2026-09-18
·
Updated
2026-09-23
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LMDeploy versions 0.9.2 through 0.15.9
Description
LMDeploy's PyTorch DistServe/PD-disaggregation control plane uses the
recv pyobj() function to deserialize messages received through a ZeroMQ PULL socket. This function relies on Python pickle deserialization, which can execute arbitrary code during object reconstruction. An attacker can provide a malicious peer address via the POST /distserve/p2p connect endpoint, forcing the server to connect to an attacker-controlled ZeroMQ endpoint and deserialize a crafted pickle payload. Because API-key authentication is disabled by default, unauthenticated remote code execution can occur with the privileges of the LMDeploy serving process. This issue specifically affects the PyTorch backend when PD-disaggregation/DistServe is enabled; standard deployments not using this path are not affected. The vulnerability involves the zmq address variable within the DistServeConnectionRequest.remote engine endpoint info object and the handle zmq recv() function.Recommendations
Update LMDeploy to version 0.16.0.
Prevent untrusted clients from accessing
/distserve/* endpoints.
Restrict DistServe HTTP and ZeroMQ control planes to trusted cluster networks.
Configure API-key authentication.
Block arbitrary outbound ZeroMQ connections from serving nodes.Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lmdeploy