RECENT STORIES:

Addressing digital sovereignty in a data-driven world
Will AI really face production reality checks in 2026?
Tradeify Announces Partnership with UFC Legend, Israel Adesanya
Tradeify Announces Partnership with UFC Legend, Israel Adesanya
Global Times: China’s GDP expands 5% to hit 140-trillion-yuan ma...
Global Times: China’s GDP expands 5% to hit 140-trillion-yuan ma...
LOGIN REGISTER
DigiconAsia
  • Features
    • Featured

      When AI and IoT converge

      When AI and IoT converge

      Thursday, January 15, 2026, 12:36 PM Asia/Singapore | Features
    • Featured

      Low-code platform enables digital-first agility

      Low-code platform enables digital-first agility

      Friday, December 26, 2025, 1:38 AM Asia/Singapore | Case Studies, Features
    • Featured

      Agents of change – the future of AI-powered e-commerce

      Agents of change – the future of AI-powered e-commerce

      Wednesday, December 24, 2025, 1:22 PM Asia/Singapore | e-Commerce, Features
  • News
    • Featured

      Bank researchers pronounce 2026 “will be toughest year for AI”

      Bank researchers pronounce 2026 “will be toughest year for AI”

      Thursday, January 22, 2026, 3:30 PM Asia/Singapore | News, Newsletter
    • Featured

      Will enhanced localization define Asia’s travel boom trends this year?

      Will enhanced localization define Asia’s travel boom trends this year?

      Wednesday, January 21, 2026, 5:14 PM Asia/Singapore | Future of Work, News, Newsletter
    • Featured

      Human supervision? Zealots argue that mortals cannot keep up with autonomous AI

      Human supervision? Zealots argue that mortals cannot keep up with autonomous AI

      Tuesday, January 20, 2026, 3:52 PM Asia/Singapore | News, Newsletter
  • Perspectives
  • Tips & Strategies
  • Whitepapers
  • Awards 2023
  • Directory
  • E-Learning

Select Page

News

Critical remote code execution flaws uncovered in major AI inference frameworks

By DigiconAsia Editors | Monday, November 17, 2025, 4:11 PM Asia/Singapore

Critical remote code execution flaws uncovered in major AI inference frameworks

Security researchers reveal widespread vulnerabilities in AI frameworks due to unsafe coding and code reuse.

A series of critical remote code execution vulnerabilities have been discovered in major AI inference frameworks, exposing systems built by big tech AI firms to severe cyber risks.

The flaws, uncovered by Oligo Security researchers, demonstrate the far-reaching consequences of unsafe coding patterns and code reuse across open-source and proprietary AI projects.​

At the heart of the issue is a pattern named “ShadowMQ”, centered around the unsafe use of the ZeroMQ messaging library’s “recv_pyobj()” method in conjunction with Python’s pickle deserialization module.

Originally identified in Meta’s Llama large language model framework (CVE-2024-50050), the vulnerability allows attackers to remotely execute arbitrary code on exposed inference servers by sending malicious data through networked sockets. The exploit could lead to a total system takeover, data theft, or the insertion of unauthorized code, such as cryptocurrency miners or backdoors.​

Not an isolated risk
The problem is especially far-reaching because the same insecure pattern is found across several widely used frameworks. Oligo’s Avi Lumelsky has highlighted that identical unsafe code was routinely copied, often verbatim, from one project to another, spreading the flaw throughout the AI software supply chain.​

Each major implementation has now received a distinct CVE identifier:

  • NVIDIA’s TensorRT-LLM was assigned CVE-2025-23254 (CVSS 8.8), patched in version 0.18.2.
  • vLLM was flagged with CVE-2025-30165 (CVSS 8.0), though its older V0 engine remains vulnerable.
  • Modular Max Server’s version was fixed following disclosure (CVE-2025-60455).
  • Meta’s Llama-stack received CVE-2024-50050 and a critical CVSS of 9.3; the company replaced the risky deserialization with a type-safe JSON implementation in version 0.0.41.
  • Microsoft’s Sarathi-Serve remains unpatched as of this writing, and SGLang has yet to implement a complete fix.​

The research also extends beyond lab scenarios. The team reportedly found thousands of exposed ZeroMQ sockets on the public internet, a number of which connected to vulnerable AI inference clusters. If compromised, these weaknesses could allow initial attackers to move laterally across newly infected AI clusters, escalating attacks throughout entire deployments.​The incident highlights the cybersecurity risks of code reuse without rigorous review, especially in the fast-moving AI landscape.

Share:

PreviousRegional survey shows strong AI adoption but mixed maturity in developer workflows
NextCQG and Webull Singapore Partner to Bring Powerful Technology to the Broker’s New Futures Trading Offering

Related Posts

Boosting digital transformation requires native data security

Boosting digital transformation requires native data security

October 22, 2020

GenAI + Predictive AI: unlocking new vistas in personalized marketing

GenAI + Predictive AI: unlocking new vistas in personalized marketing

August 23, 2023

Retaining savvy digital consumers’ trust in APAC’s banking and financial services industry

Retaining savvy digital consumers’ trust in APAC’s banking and financial services industry

August 16, 2022

Satellite communications as the fabric of the Asia Pacific economy

Satellite communications as the fabric of the Asia Pacific economy

May 20, 2020

Leave a reply Cancel reply

You must be logged in to post a comment.

Awards Nomination Banner

gamification list

PARTICIPATE NOW

top placement

Whitepapers

  • Achieve Modernization Without the Complexity

    Achieve Modernization Without the Complexity

    Transforming IT infrastructure is crucial …Download Whitepaper
  • 5 Steps to Boost IT Infrastructure Reliability

    5 Steps to Boost IT Infrastructure Reliability

    In today's fast-evolving tech landscape, …Download Whitepaper
  • Simplify Payroll Setup for Your Small Business

    Simplify Payroll Setup for Your Small Business

    In our free guide, "How …Download Whitepaper
  • Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Download Whitepaper

Middle Placement

Case Studies

  • When 24/7 engagement means so much to students: University of Malaysia Nottingham

    When 24/7 engagement means so much to students: University of Malaysia Nottingham

    That is what prompted the …Read More
  • Harnessing the data lakehouse and AI to revolutionize customer experience

    Harnessing the data lakehouse and AI to revolutionize customer experience

    UOB achieved 99% cash availability …Read More
  • Bhutan sovereign wealth fund pilots offline data relay to stabilize distributed-ledger challenges

    Bhutan sovereign wealth fund pilots offline data relay to stabilize distributed-ledger challenges

    Amid remote connectivity gaps in …Read More
  • Low-code platform enables digital-first agility

    Low-code platform enables digital-first agility

    Few industries demand agility and …Read More

Bottom Sidebar

Other News

  • Tradeify Announces Partnership with UFC Legend, Israel Adesanya

    January 23, 2026
    Adesanya joins Tradeify as Global …Read More »
  • Tradeify Announces Partnership with UFC Legend, Israel Adesanya

    January 23, 2026
    Adesanya joins Tradeify as Global …Read More »
  • Global Times: China’s GDP expands 5% to hit 140-trillion-yuan mark in 2025, meeting growth target despite serious headwinds

    January 22, 2026
    BEIJING, Jan. 22, 2026 /PRNewswire/ …Read More »
  • Global Times: China’s GDP expands 5% to hit 140-trillion-yuan mark in 2025, meeting growth target despite serious headwinds

    January 22, 2026
    BEIJING, Jan. 22, 2026 /PRNewswire/ …Read More »
  • Teleport raises USD 50 million pre-IPO capital at USD 500 million valuation to scale model globally

    January 22, 2026
    Teleport set to accelerate the …Read More »
  • Our Brands
  • CybersecAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 DigiconAsia All Rights Reserved.