THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-5h8j-6crg-7rmw (critical) — LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy

[GHSA] GHSA-5h8j-6crg-7rmw (critical) — LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy

medgithub_advisoriesPublished 2026-09-16

GHSA-5h8j-6crg-7rmw Severity: critical CVE: CVE-2025-59953

LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy

### Description

The LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC communications. In its core functionality call_and_response(), I found it will directly use the pickles.loads() to de

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-5h8j-6crg-7rmw