Impact
LMDeploy allows an attacker who can reach its DistServe API to trigger Python pickle deserialization on the server. The vulnerable function receives data through a ZeroMQ PULL socket and uses PyZMQ’s recv_pyobj, which reconstructs objects via the pickle module. Because pickle execution can run arbitrary code, an attacker can craft a malicious payload that, when deserialized, executes with the same privileges as the LMDeploy serving process. This results in complete compromise of the system running the service, including data disclosure, modification, or further lateral movement. The weakness is categorized as insecure deserialization (CWE‑502).
Affected Systems
The vulnerability affects InternLM’s LMDeploy package, specifically from version 0.9.2 up to but not including 0.16.0, when the PyTorch DistServe/PD‑disaggregation control plane is enabled. Ordinary deployments that do not use the disaggregated serving path do not expose this data flow.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, and the EPSS score is not available, so the exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog. An attacker requires network reachability to the DistServe HTTP endpoint (/distserve/p2p_connect) and, optionally, the ability to spin up a ZMQ server that the victim connects to. If API‑key authentication is not enabled, the attack is unauthenticated and can be executed from any host that can reach the exposed API. Once the payload is received, code execution occurs immediately on the service process.
OpenCVE Enrichment
Github GHSA