VAITP Dataset

← Back to the dataset

CVE-2025-66455

Unauthenticated RCE via pickle deserialization in LMDeploy DistServe.

  • CVSS 9.8
  • 502
  • Input Validation and Sanitization
  • Remote

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize messages received through a ZeroMQ PULL socket. PyZMQ implements `recv_pyobj()` using Python pickle deserialization, which can execute arbitrary code while reconstructing an object. The peer address used by the receiver was supplied through the `POST /distserve/p2p_connect` HTTP endpoint. An attacker who could reach an affected DistServe API server could cause the server to connect to an attacker-controlled ZeroMQ endpoint and deserialize a crafted pickle payload. API-key authentication is not enabled unless the operator explicitly configures it. As a result, affected DistServe deployments without API keys allowed unauthenticated remote code execution with the privileges of the LMDeploy serving process. This issue affects the PyTorch backend when PD-disaggregation/DistServe is enabled. Ordinary deployments that do not use the affected disaggregated-serving path do not expose this data flow. The fix was released in LMDeploy 0.16.0. Users who cannot upgrade immediately should prevent untrusted clients from reaching `/distserve/*` endpoints, restrict the DistServe HTTP and ZeroMQ control planes to trusted cluster networks, configure API-key authentication, and block arbitrary outbound ZeroMQ connections from serving nodes. These measures reduce exposure but do not make pickle deserialization safe.

CWE
502
CVSS base score
9.8
Published
2026-09-18
OWASP
A08 Software and Data Integrity Failures
Orthogonal defect classification
Timing/Serialization
Code defect classification
Serialization Issues
Category
Input Validation and Sanitization
Subcategory
Insecure Parsing or Deserialization
Accessibility scope
Remote
Impact
Arbitrary Code Execution
Affected component
LMDeploy
Fixed by upgrading
Yes

Solution

Upgrade LMDeploy to version 0.16.0 or newer.

Vulnerable code sample

import zmq
from flask import Flask, request, jsonify

app = Flask(__name__)

@app.route('/distserve/p2p_connect', methods=['POST'])
def p2p_connect():
    peer_addr = request.json.get('peer_addr')
    if not peer_addr:
        return jsonify({'error': 'missing peer_addr'}), 400

    ctx = zmq.Context()
    socket = ctx.socket(zmq.PULL)
    socket.connect(peer_addr)

    # VULNERABLE: using pickle deserialization on untrusted data
    obj = socket.recv_pyobj()
    # process obj...
    return jsonify({'status': 'ok'}), 200

Patched code sample

import zmq
import json
from flask import Flask, request, jsonify

app = Flask(__name__)

@app.route('/distserve/p2p_connect', methods=['POST'])
def p2p_connect():
    peer_addr = request.json.get('peer_addr')
    if not peer_addr:
        return jsonify({'error': 'missing peer_addr'}), 400

    ctx = zmq.Context()
    socket = ctx.socket(zmq.PULL)
    socket.connect(peer_addr)

    # FIX: receive raw bytes and safely deserialize JSON
    raw = socket.recv()
    try:
        obj = json.loads(raw.decode('utf-8'))
    except (json.JSONDecodeError, UnicodeDecodeError):
        return jsonify({'error': 'invalid payload'}), 400
    # process obj...
    return jsonify({'status': 'ok'}), 200

Payload

__VAITP_MODEL_REFUSED__

Cite this entry

@misc{vaitp:cve202566455,
  title        = {{Unauthenticated RCE via pickle deserialization in LMDeploy DistServe.}},
  author       = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
  year         = {2026},
  note         = {VAITP Python Vulnerability Dataset, entry CVE-2025-66455},
  howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2025-66455/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::