CVE-2025-66455: LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
(updated )
LMDeploy’s PyTorch DistServe/PD-disaggregation control plane used
recv_pyobj() to deserialize messages received through a ZeroMQ PULL
socket. PyZMQ implements recv_pyobj() using Python pickle
deserialization, which can execute arbitrary code while reconstructing
an object.
The peer address used by the receiver was supplied through the
POST /distserve/p2p_connect HTTP endpoint. An attacker who could reach
an affected DistServe API server could cause the server to connect to an
attacker-controlled ZeroMQ endpoint and deserialize a crafted pickle
payload.
API-key authentication is not enabled unless the operator explicitly configures it. As a result, affected DistServe deployments without API keys allowed unauthenticated remote code execution with the privileges of the LMDeploy serving process.
This issue affects the PyTorch backend when PD-disaggregation/DistServe is enabled. Ordinary deployments that do not use the affected disaggregated-serving path do not expose this data flow.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-66455 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →