Skip to finding
important · AI serving — LMDeploy

LMDeploy DistServe can connect to an attacker-controlled ZeroMQ peer and unpickle code as its serving process.

Affects

LMDeploy, an AI-model deployment and inference-serving framework, when using its PyTorch DistServe or prefill/decode-disaggregation control plane.

On a relevant deployment left at its documented no-API-key default, an unauthenticated caller supplies a ZeroMQ address and returns a malicious pickle object over the resulting outbound connection.

Detail and 1 source
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 21, 2026