RECENT STORIES:

Addressing digital sovereignty in a data-driven world
When AI treats search terms as a command instead: risk alert
CFTEC, AEOTrade Co-host China-Singapore Digital Trade Roadshow at WCIF...
Arctech Secures Global No. 2 in Solar Trackers for Second Consecutive ...
30-Day Countdown Begins: 4th CISCE to Open in Beijing on June 22
HiFS 2026: Upgrading Four Major Digital Finance Solutions to Accelerat...
LOGIN REGISTER
DigiconAsia
  • Features
    • Featured

      Agentic RAG: Key to turning APAC’s AI pilots into profits?

      Agentic RAG: Key to turning APAC’s AI pilots into profits?

      Wednesday, May 20, 2026, 9:54 AM Asia/Singapore | Features
    • Featured

      Defining the future of customer and employee experience

      Defining the future of customer and employee experience

      Tuesday, May 19, 2026, 11:16 PM Asia/Singapore | Features, Future of Work, Newsletter
    • Featured

      How a Vietnamese D2C retailer built its own secure digital infrastructure

      How a Vietnamese D2C retailer built its own secure digital infrastructure

      Friday, May 15, 2026, 2:17 PM Asia/Singapore | Case Studies, Features
  • News
    • Featured

      When AI treats search terms as a command instead: risk alert

      When AI treats search terms as a command instead: risk alert

      Monday, May 25, 2026, 2:46 PM Asia/Singapore | News
    • Featured

      Static search bars to evolve into continuous, AI-driven multimodal assistants

      Static search bars to evolve into continuous, AI-driven multimodal assistants

      Thursday, May 21, 2026, 6:57 PM Asia/Singapore | News
    • Featured

      CALB upgrades data platform to support analytics, security, and battery lifecycle tracking

      CALB upgrades data platform to support analytics, security, and battery lifecycle tracking

      Thursday, May 21, 2026, 2:44 PM Asia/Singapore | Case Studies, News
  • Perspectives
  • Tips & Strategies
  • Whitepapers
  • Directory
  • E-Learning

Select Page

News

Critical remote code execution flaws uncovered in major AI inference frameworks

By DigiconAsia Editors | Monday, November 17, 2025, 4:11 PM Asia/Singapore

Critical remote code execution flaws uncovered in major AI inference frameworks

Security researchers reveal widespread vulnerabilities in AI frameworks due to unsafe coding and code reuse.

A series of critical remote code execution vulnerabilities have been discovered in major AI inference frameworks, exposing systems built by big tech AI firms to severe cyber risks.

The flaws, uncovered by Oligo Security researchers, demonstrate the far-reaching consequences of unsafe coding patterns and code reuse across open-source and proprietary AI projects.​

At the heart of the issue is a pattern named “ShadowMQ”, centered around the unsafe use of the ZeroMQ messaging library’s “recv_pyobj()” method in conjunction with Python’s pickle deserialization module.

Originally identified in Meta’s Llama large language model framework (CVE-2024-50050), the vulnerability allows attackers to remotely execute arbitrary code on exposed inference servers by sending malicious data through networked sockets. The exploit could lead to a total system takeover, data theft, or the insertion of unauthorized code, such as cryptocurrency miners or backdoors.​

Not an isolated risk
The problem is especially far-reaching because the same insecure pattern is found across several widely used frameworks. Oligo’s Avi Lumelsky has highlighted that identical unsafe code was routinely copied, often verbatim, from one project to another, spreading the flaw throughout the AI software supply chain.​

Each major implementation has now received a distinct CVE identifier:

  • NVIDIA’s TensorRT-LLM was assigned CVE-2025-23254 (CVSS 8.8), patched in version 0.18.2.
  • vLLM was flagged with CVE-2025-30165 (CVSS 8.0), though its older V0 engine remains vulnerable.
  • Modular Max Server’s version was fixed following disclosure (CVE-2025-60455).
  • Meta’s Llama-stack received CVE-2024-50050 and a critical CVSS of 9.3; the company replaced the risky deserialization with a type-safe JSON implementation in version 0.0.41.
  • Microsoft’s Sarathi-Serve remains unpatched as of this writing, and SGLang has yet to implement a complete fix.​

The research also extends beyond lab scenarios. The team reportedly found thousands of exposed ZeroMQ sockets on the public internet, a number of which connected to vulnerable AI inference clusters. If compromised, these weaknesses could allow initial attackers to move laterally across newly infected AI clusters, escalating attacks throughout entire deployments.​The incident highlights the cybersecurity risks of code reuse without rigorous review, especially in the fast-moving AI landscape.

Share:

PreviousRegional survey shows strong AI adoption but mixed maturity in developer workflows
NextCQG and Webull Singapore Partner to Bring Powerful Technology to the Broker’s New Futures Trading Offering

Related Posts

Goodbye Blue Screen of Death. Hello Black Death in Windows 11

Goodbye Blue Screen of Death. Hello Black Death in Windows 11

July 2, 2025

Wielding a double-edge sword in circumventing data privacy compliance: anonymization

Wielding a double-edge sword in circumventing data privacy compliance: anonymization

February 23, 2022

Buying an Aston Martin the e-commerce way in the UK

Buying an Aston Martin the e-commerce way in the UK

February 23, 2021

Amid continual global unrest and myriad uncertainties, CEOs need a brave front

Amid continual global unrest and myriad uncertainties, CEOs need a brave front

October 9, 2024

Leave a reply Cancel reply

You must be logged in to post a comment.

Awards Nomination Banner

gamification list

PARTICIPATE NOW

top placement

Whitepapers

  • Achieve Modernization Without the Complexity

    Achieve Modernization Without the Complexity

    Transforming IT infrastructure is crucial …Download Whitepaper
  • 5 Steps to Boost IT Infrastructure Reliability

    5 Steps to Boost IT Infrastructure Reliability

    In today's fast-evolving tech landscape, …Download Whitepaper
  • Simplify Payroll Setup for Your Small Business

    Simplify Payroll Setup for Your Small Business

    In our free guide, "How …Download Whitepaper
  • Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Download Whitepaper

Middle Placement

Case Studies

  • CALB upgrades data platform to support analytics, security, and battery lifecycle tracking

    CALB upgrades data platform to support analytics, security, and battery lifecycle tracking

    Deploying a petabyte-scale data lake …Read More
  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your …Read More
  • Liverpool FC to deliver more personalized, real-time digital fan experiences with AI

    Liverpool FC to deliver more personalized, real-time digital fan experiences with AI

    The football club will deepen …Read More
  • Balancing brand heritage and modern service with AI-powered customer experience

    Balancing brand heritage and modern service with AI-powered customer experience

    Balancing brand heritage and modern …Read More

Bottom Sidebar

Other News

  • CFTEC, AEOTrade Co-host China-Singapore Digital Trade Roadshow at WCIFIT

    May 23, 2026
    CHONGQING, China, May 23, 2026 …Read More »
  • Arctech Secures Global No. 2 in Solar Trackers for Second Consecutive Year, Retains Top Position in EMEA

    May 23, 2026
    KUNSHAN, China, May 23, 2026 …Read More »
  • 30-Day Countdown Begins: 4th CISCE to Open in Beijing on June 22

    May 23, 2026
    BEIJING, May 23, 2026 /PRNewswire/ …Read More »
  • HiFS 2026: Upgrading Four Major Digital Finance Solutions to Accelerate Financial Institutions Toward Agentic Banking

    May 23, 2026
    SHANGHAI, May 23, 2026 /PRNewswire/ …Read More »
  • With Children’s Day approaching, what has Yiwu, the “world’s supermarket”, prepared for children worldwide?

    May 23, 2026
    YIWU, China, May 23, 2026 …Read More »
  • Our Brands
  • CybersecAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 DigiconAsia All Rights Reserved.