important · AI serving — LMDeploy
LMDeploy DistServe can connect to an attacker-controlled ZeroMQ peer and unpickle code as its serving process.
Affects
LMDeploy, an AI-model deployment and inference-serving framework, when using its PyTorch DistServe or prefill/decode-disaggregation control plane.
On a relevant deployment left at its documented no-API-key default, an unauthenticated caller supplies a ZeroMQ address and returns a malicious pickle object over the resulting outbound connection.
Detail and 1 source
Fixed versions are identified, but no public exploit demonstration is held.