External risk intelligence

LMDeploy PyTorch DistServe Unsafe Deserialization Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-66455

The vulnerability exists in the DistServe/PD-disaggregation control plane, which is an optional, specific configuration of the LMDeploy toolkit rather than a standard public-facing web interface. While reachable via network, it is typically restricted to internal cluster communications, and its exposure depends on whether the operator specifically enables this disaggregated serving path.

Deserialization

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in the LMDeploy toolkit, specifically within its PyTorch DistServe component. This issue could allow an unauthenticated attacker to execute arbitrary code on affected systems by sending a specially crafted message. The primary concern is confirming if this specific disaggregated serving path is enabled and exposed in your environment, as ordinary deployments are not impacted.

  • Unauthenticated code execution risk in LMDeploy's DistServe.
  • Affects specific, optionally enabled serving configurations.
  • Confirm relevance if optional disaggregated serving is active.

Attack Path

How an attacker could exploit the issue

An attacker could reach an affected LMDeploy server that is configured with the DistServe PyTorch disaggregation feature. By sending a specially crafted message to a specific API endpoint, the attacker can trick the server into connecting to a remote location controlled by the attacker. This allows the attacker to send a malicious payload that gets deserialized, leading to arbitrary code execution on the server. This attack is possible if API-key authentication is not enabled.

  • Network access to DistServe API required.
  • Server connects to attacker-controlled endpoint.
  • Unauthenticated remote code execution possible.

Live Threat

Current exploitation, exposure, and threat context

When LMDeploy's DistServe/PD-disaggregation control plane is enabled and unauthenticated, an attacker could connect to a vulnerable server and trigger arbitrary code execution with the privileges of the LMDeploy serving process by sending a crafted pickle payload. This risk is present when API-key authentication is not configured and untrusted clients can reach the affected API endpoints.

  • Serving process code execution.
  • Unauthenticated network connections.
  • Compromise of the serving environment.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for LMDeploy, particularly those managing PyTorch backends with the DistServe/PD-disaggregation feature enabled, should lead the response. The first step is to identify all instances of this specific configuration, determine their network reachability and business criticality, and then assign ownership to the accountable team for planning remediation.

  • Own by application or platform teams.
  • Verify DistServe/PD-disaggregation usage and reachability.
  • Plan remediation or apply network/authentication controls.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is LMDeploy?

LMDeploy is a software toolkit designed for compressing, deploying, and serving large language models. It provides infrastructure to manage how these models run and respond to requests. The vulnerability affects a specific component called DistServe, which is used for disaggregated serving, meaning it is only a factor if you have explicitly configured your deployment to use that advanced architecture.

What does CWE-502 mean for CVE-2025-66455?

CWE-502 refers to 'Deserialization of Untrusted Data.' In this context, the software uses a Python function that automatically reconstructs objects from incoming data. If an attacker sends a specially crafted file or message, the system may inadvertently execute hidden instructions contained within that data. This allows the attacker to run commands on your server with the same permissions as the application itself.

How is this vulnerability triggered?

An attacker must reach the DistServe API and provide an address for the server to connect to via an HTTP endpoint. The server then attempts to receive data from that attacker-controlled source. This process only occurs if you are using the specific DistServe/PD-disaggregation path; standard deployments of LMDeploy that do not use this disaggregated feature are not susceptible to this data flow.

Is my system at risk?

According to Halo Surface Signal, this vulnerability has a 'Possible' risk status. It only impacts the DistServe control plane, which is an optional feature. While the vulnerability is reachable over a network, it is typically restricted to internal cluster communications. Your risk is highest if this specific control plane is enabled, lacks API-key authentication, and is reachable by untrusted network traffic.

How should I respond to this advisory?

First, verify if your environment uses the DistServe or PD-disaggregation feature, as basic deployments are not affected. If you are using this feature, prioritize updating to LMDeploy version 0.16.0 or later. If an immediate update is not possible, restrict access to the affected API endpoints, ensure API-key authentication is enabled, and block any unauthorized outbound network connections from your serving nodes.

References