Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in the LMDeploy toolkit, specifically within its PyTorch DistServe component. This issue could allow an unauthenticated attacker to execute arbitrary code on affected systems by sending a specially crafted message. The primary concern is confirming if this specific disaggregated serving path is enabled and exposed in your environment, as ordinary deployments are not impacted.
- Unauthenticated code execution risk in LMDeploy's DistServe.
- Affects specific, optionally enabled serving configurations.
- Confirm relevance if optional disaggregated serving is active.
Attack Path
How an attacker could exploit the issue
An attacker could reach an affected LMDeploy server that is configured with the DistServe PyTorch disaggregation feature. By sending a specially crafted message to a specific API endpoint, the attacker can trick the server into connecting to a remote location controlled by the attacker. This allows the attacker to send a malicious payload that gets deserialized, leading to arbitrary code execution on the server. This attack is possible if API-key authentication is not enabled.
- Network access to DistServe API required.
- Server connects to attacker-controlled endpoint.
- Unauthenticated remote code execution possible.
Live Threat
Current exploitation, exposure, and threat context
When LMDeploy's DistServe/PD-disaggregation control plane is enabled and unauthenticated, an attacker could connect to a vulnerable server and trigger arbitrary code execution with the privileges of the LMDeploy serving process by sending a crafted pickle payload. This risk is present when API-key authentication is not configured and untrusted clients can reach the affected API endpoints.
- Serving process code execution.
- Unauthenticated network connections.
- Compromise of the serving environment.
Operational Fix
Recommended remediation, mitigation, and detection steps
Teams responsible for LMDeploy, particularly those managing PyTorch backends with the DistServe/PD-disaggregation feature enabled, should lead the response. The first step is to identify all instances of this specific configuration, determine their network reachability and business criticality, and then assign ownership to the accountable team for planning remediation.
- Own by application or platform teams.
- Verify DistServe/PD-disaggregation usage and reachability.
- Plan remediation or apply network/authentication controls.