Description
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC communications. In its core functionality call_and_response(), I found it will directly use the pickles.loads() to deserialize the received messages without any sanitization, hence resulting in a remote code execution vulnerability by this RPC server. Version 0.10.2 contains a patch.
Published: 2026-09-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The privilege‑elevating flaw stems from the LMdeploy RPC server's use of Python's pickle.loads without any sanitization, allowing an attacker to send crafted serialized data that is executed on the server. This vulnerability can enable full remote code execution on systems that expose the RPC service, compromising confidentiality, integrity, and availability of the entire deployment.

Affected Systems

InternLM lmdeploy, versions 0.9.1 up to and including 0.10.1 are affected, while version 0.10.2 and later contain the fix.

Risk and Exploitability

The CVSS score of 9.8 marks it as critical; the EPSS score of less than 1% indicates a low current exploitation probability, and it is not yet listed in the CISA KEV catalog. The attack vector is likely remote, via the RPC interface exposed by the service, and an attacker only needs the ability to send a crafted payload to the RPC endpoint to trigger the vulnerability.

Generated by OpenCVE AI on September 18, 2026 at 00:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update lmdeploy to version 0.10.2 or later to apply the patch.
  • If an update is not immediately possible, disable the RPC server or restrict its network exposure to trusted hosts only.
  • Replace or wrap any use of pickle.loads with a safe deserialization mechanism or validate input before deserialization to prevent arbitrary code execution.

Generated by OpenCVE AI on September 18, 2026 at 00:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5h8j-6crg-7rmw LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Internlm
Internlm lmdeploy
Vendors & Products Internlm
Internlm lmdeploy

Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC communications. In its core functionality call_and_response(), I found it will directly use the pickles.loads() to deserialize the received messages without any sanitization, hence resulting in a remote code execution vulnerability by this RPC server. Version 0.10.2 contains a patch.
Title LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Internlm Lmdeploy
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T18:05:59.705Z

Reserved: 2025-09-23T14:33:49.506Z

Link: CVE-2025-59953

cve-icon Vulnrichment

Updated: 2026-09-18T18:05:52.973Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T16:17:03.010

Modified: 2026-09-24T21:25:27.050

Link: CVE-2025-59953

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:30:03Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data