Description
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize messages received through a ZeroMQ PULL socket. PyZMQ implements `recv_pyobj()` using Python pickle deserialization, which can execute arbitrary code while reconstructing an object. The peer address used by the receiver was supplied through the `POST /distserve/p2p_connect` HTTP endpoint. An attacker who could reach an affected DistServe API server could cause the server to connect to an attacker-controlled ZeroMQ endpoint and deserialize a crafted pickle payload. API-key authentication is not enabled unless the operator explicitly configures it. As a result, affected DistServe deployments without API keys allowed unauthenticated remote code execution with the privileges of the LMDeploy serving process. This issue affects the PyTorch backend when PD-disaggregation/DistServe is enabled. Ordinary deployments that do not use the affected disaggregated-serving path do not expose this data flow. The fix was released in LMDeploy 0.16.0. Users who cannot upgrade immediately should prevent untrusted clients from reaching `/distserve/*` endpoints, restrict the DistServe HTTP and ZeroMQ control planes to trusted cluster networks, configure API-key authentication, and block arbitrary outbound ZeroMQ connections from serving nodes. These measures reduce exposure but do not make pickle deserialization safe.
Published: 2026-09-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

LMDeploy allows an attacker who can reach its DistServe API to trigger Python pickle deserialization on the server. The vulnerable function receives data through a ZeroMQ PULL socket and uses PyZMQ’s recv_pyobj, which reconstructs objects via the pickle module. Because pickle execution can run arbitrary code, an attacker can craft a malicious payload that, when deserialized, executes with the same privileges as the LMDeploy serving process. This results in complete compromise of the system running the service, including data disclosure, modification, or further lateral movement. The weakness is categorized as insecure deserialization (CWE‑502).

Affected Systems

The vulnerability affects InternLM’s LMDeploy package, specifically from version 0.9.2 up to but not including 0.16.0, when the PyTorch DistServe/PD‑disaggregation control plane is enabled. Ordinary deployments that do not use the disaggregated serving path do not expose this data flow.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, and the EPSS score is not available, so the exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog. An attacker requires network reachability to the DistServe HTTP endpoint (/distserve/p2p_connect) and, optionally, the ability to spin up a ZMQ server that the victim connects to. If API‑key authentication is not enabled, the attack is unauthenticated and can be executed from any host that can reach the exposed API. Once the payload is received, code execution occurs immediately on the service process.

Generated by OpenCVE AI on September 19, 2026 at 12:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade LMDeploy to version 0.16.0 or later to apply the official fix
  • Restrict network access to /distserve/* endpoints, allowing only trusted internal clients to reach them
  • Configure API‑key authentication for all DistServe API calls to prevent unauthenticated usage
  • Block arbitrary outbound ZeroMQ connections from serving nodes to stop connections to attacker‑controlled endpoints

Generated by OpenCVE AI on September 19, 2026 at 12:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2vh9-42vm-xmv2 LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
History

Sun, 20 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Internlm
Internlm lmdeploy
Vendors & Products Internlm
Internlm lmdeploy

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize messages received through a ZeroMQ PULL socket. PyZMQ implements `recv_pyobj()` using Python pickle deserialization, which can execute arbitrary code while reconstructing an object. The peer address used by the receiver was supplied through the `POST /distserve/p2p_connect` HTTP endpoint. An attacker who could reach an affected DistServe API server could cause the server to connect to an attacker-controlled ZeroMQ endpoint and deserialize a crafted pickle payload. API-key authentication is not enabled unless the operator explicitly configures it. As a result, affected DistServe deployments without API keys allowed unauthenticated remote code execution with the privileges of the LMDeploy serving process. This issue affects the PyTorch backend when PD-disaggregation/DistServe is enabled. Ordinary deployments that do not use the affected disaggregated-serving path do not expose this data flow. The fix was released in LMDeploy 0.16.0. Users who cannot upgrade immediately should prevent untrusted clients from reaching `/distserve/*` endpoints, restrict the DistServe HTTP and ZeroMQ control planes to trusted cluster networks, configure API-key authentication, and block arbitrary outbound ZeroMQ connections from serving nodes. These measures reduce exposure but do not make pickle deserialization safe.
Title LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Internlm Lmdeploy
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T19:54:19.941Z

Reserved: 2025-12-01T18:44:35.640Z

Link: CVE-2025-66455

cve-icon Vulnrichment

Updated: 2026-09-18T19:54:14.828Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T18:17:04.420

Modified: 2026-09-23T18:12:04.247

Link: CVE-2025-66455

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:00:08Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data