PT-2026-95544 · Lmdeploy · Lmdeploy

CVE-2025-66455

·

Published

2026-09-18

·

Updated

2026-09-23

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LMDeploy versions 0.9.2 through 0.15.9
Description LMDeploy's PyTorch DistServe/PD-disaggregation control plane uses the recv pyobj() function to deserialize messages received through a ZeroMQ PULL socket. This function relies on Python pickle deserialization, which can execute arbitrary code during object reconstruction. An attacker can provide a malicious peer address via the POST /distserve/p2p connect endpoint, forcing the server to connect to an attacker-controlled ZeroMQ endpoint and deserialize a crafted pickle payload. Because API-key authentication is disabled by default, unauthenticated remote code execution can occur with the privileges of the LMDeploy serving process. This issue specifically affects the PyTorch backend when PD-disaggregation/DistServe is enabled; standard deployments not using this path are not affected. The vulnerability involves the zmq address variable within the DistServeConnectionRequest.remote engine endpoint info object and the handle zmq recv() function.
Recommendations Update LMDeploy to version 0.16.0. Prevent untrusted clients from accessing /distserve/* endpoints. Restrict DistServe HTTP and ZeroMQ control planes to trusted cluster networks. Configure API-key authentication. Block arbitrary outbound ZeroMQ connections from serving nodes.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66455
GHSA-2VH9-42VM-XMV2

Affected Products

Lmdeploy