THREAT OPS › Threat News › [GHSA] GHSA-5h8j-6crg-7rmw (critical) — LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
[GHSA] GHSA-5h8j-6crg-7rmw (critical) — LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
GHSA-5h8j-6crg-7rmw Severity: critical CVE: CVE-2025-59953
LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
### Description
The LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC communications. In its core functionality call_and_response(), I found it will directly use the pickles.loads() to de
MITRE ATT&CK techniques
- Reverse ShellAML.T0072
Indicators of compromise
- CVE-2025-59953cve
- 202.112.47.27ipv4
Original source: https://github.com/advisories/GHSA-5h8j-6crg-7rmw