Description
LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes with pickle.loads(), and the isinstance check against DistServeCacheFreeRequest runs only after deserialization has already completed. The peer that supplies those bytes is caller-controlled: p2p_connect passes remote_engine_endpoint_info.zmq_address from the request body to connect() on the ZMQ PULL socket, and the POST /distserve/p2p_initialize and /distserve/p2p_connect endpoints in lmdeploy/serve/openai/api_server.py apply no authentication unless the server is started with api_keys, which defaults to None. A remote attacker can direct an engine to pull from a ZMQ endpoint under their control and execute arbitrary code in the engine process. Deployments that do not enable disaggregated serving are not affected, because the receive loop is only started once the migration backend accepts the connection.
Published: 2026-08-19
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

LMDeploy deserializes data received from a peer‑to‑peer ZMQ connection with Python's unsafe pickle.loads() before validating the request type, enabling an attacker to send a malicious byte stream that executes arbitrary Python code in the engine process. This flaw is a classic unsafe deserialization vulnerability (CWE‑502) that directly permits an attacker to gain full control of a vulnerable deployment.

Affected Systems

The vulnerability exists in the InternLM lmdeploy product when the disaggregated serving mode is enabled, such as in version 0.15.0 and earlier. Any deployment that activates the p2p_connect flow—triggered via POST /distserve/p2p_initialize and /distserve/p2p_connect—exposes the flaw if authentication is disabled and the engine accepts connections from a caller‑controlled ZMQ address.

Risk and Exploitability

With a CVSS score of 9.3 the flaw is classified as critical. Because the endpoint that supplies the serialized data is selected by the caller and the API endpoints do not require authentication by default, a remote attacker can trivially supply a malicious ZMQ endpoint and trigger execution of arbitrary code in the engine. Although the EPSS score is not available and the vulnerability is not listed in KEV, the lack of authentication and the nature of the deserialization mean that exploitation is straightforward and the risk to affected systems is extremely high.

Generated by OpenCVE AI on August 20, 2026 at 08:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade lmdeploy to version 0.16.0 or later, which removes the unsafe pickle deserialization in the peer connector.
  • If an upgrade is not possible, disable the disaggregated serving mode or configure the API with authentication keys so that the POST /distserve/p2p_initialize and /distserve/p2p_connect endpoints reject untrusted requests.
  • Restrict the ZMQ endpoint address that the engine accepts connections from to known, trusted hosts, and do not allow arbitrary caller‑specified addresses.
  • If internal code must still deserialize peer messages, replace pickle.loads() with a safe, non‑eval serialization format such as JSON or MessagePack, and add rigorous type validation before execution.

Generated by OpenCVE AI on August 20, 2026 at 08:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes with pickle.loads(), and the isinstance check against DistServeCacheFreeRequest runs only after deserialization has already completed. The peer that supplies those bytes is caller-controlled: p2p_connect passes remote_engine_endpoint_info.zmq_address from the request body to connect() on the ZMQ PULL socket, and the POST /distserve/p2p_initialize and /distserve/p2p_connect endpoints in lmdeploy/serve/openai/api_server.py apply no authentication unless the server is started with api_keys, which defaults to None. A remote attacker can direct an engine to pull from a ZMQ endpoint under their control and execute arbitrary code in the engine process. Deployments that do not enable disaggregated serving are not affected, because the receive loop is only started once the migration backend accepts the connection.
Title LMDeploy Remote Code Execution via Unsafe Pickle Deserialization in the Disaggregated Serving Peer Connector
First Time appeared Internlm
Internlm lmdeploy
Weaknesses CWE-502
CPEs cpe:2.3:a:internlm:lmdeploy:*:*:*:*:*:*:*:*
Vendors & Products Internlm
Internlm lmdeploy
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Internlm Lmdeploy
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-21T11:21:12.965Z

Reserved: 2026-08-19T21:24:37.594Z

Link: CVE-2026-76850

cve-icon Vulnrichment

Updated: 2026-08-20T14:08:36.764Z

cve-icon NVD

Status : Received

Published: 2026-08-19T22:17:28.123

Modified: 2026-08-20T15:18:38.700

Link: CVE-2026-76850

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T08:30:04Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data