External risk intelligence

LMDeploy RPC Server Deserialization Vulnerability Leads to Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-59953

LMDeploy is used to deploy and serve large language models. While the RPC server is designed for internal communication between components of the model serving infrastructure, it is plausibly reachable from the internet in some deployments where model endpoints are exposed, though it is not inherently a public-facing gateway or identity service.

Deserialization

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in LMDeploy, a toolkit used for deploying and serving large language models. The issue involves the direct deserialization of received messages without proper validation, potentially allowing for remote code execution. This could impact the integrity and availability of your large language model deployments.

  • Code can be run remotely via model serving.
  • Critical flaw affects model serving infrastructure.
  • Confirm LMDeploy use and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit a vulnerability in LMDeploy's RPC server by sending specially crafted messages. The server deserializes these messages without proper checks, allowing an attacker to execute arbitrary code remotely. This could occur if the RPC server is exposed, potentially allowing an attacker to gain control over the affected system.

  • RPC server exposed externally.
  • Deserializing unsanitized messages.
  • Remote code execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an unprotected RPC server in LMDeploy could allow remote code execution. This vulnerability could expose system data and service behavior by allowing an attacker to run arbitrary code on the server when processing unverified messages.

  • System data and service behavior at risk.
  • Unsanitized messages could trigger execution.
  • Potential for full system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

In real-world scenarios, the Platform Engineering or MLOps team responsible for managing the large language model (LLM) infrastructure is likely to own this vulnerability. The initial practical step is to identify all instances of LMDeploy within the environment, determine their exposure (especially if the RPC server is reachable externally), and confirm their criticality. Once identified, the accountable owner must be located to plan remediation, which may involve coordinating with vendors or scheduling maintenance windows.

  • Own by platform or MLOps team.
  • Verify LMDeploy reachability and criticality.
  • Plan vendor coordination or maintenance.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is LMDeploy?

LMDeploy is a software toolkit engineered to compress, deploy, and serve large language models. Developers and machine learning engineers use it to optimize model performance and manage the infrastructure required to host AI models for inference.

What does CVE-2025-59953 mean by deserialization vulnerability?

This vulnerability, classified as CWE-502 (Deserialization of Untrusted Data), occurs because the software uses 'pickle.loads()' to process incoming data without checking it first. Because this function can instantiate complex Python objects, an attacker can craft a malicious message that forces the server to execute arbitrary commands upon receipt.

How can an attacker trigger this LMDeploy bug?

The flaw is triggered when the RPC server receives and processes a specifically crafted message. It is important to note that simply having LMDeploy installed does not trigger the bug; the system must be actively running the vulnerable AsyncRPCServer component and be reachable by the attacker to process the malicious input.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal notes that while the RPC server is intended for internal component communication, it may be reachable from the internet if your model endpoints are exposed. If your LMDeploy deployment is configured with an externally accessible RPC interface, it faces a higher level of risk compared to instances isolated within an internal network.

Do I need to update my LMDeploy version?

Yes. If you are running a version between 0.9.1 and 0.10.1, you should prioritize upgrading to version 0.10.2 or later, which contains the necessary security patch. First, locate all instances of LMDeploy in your environment and coordinate with your MLOps or platform engineering teams to verify their current network exposure before applying the update.

References