RECENT STORIES:

Addressing digital sovereignty in a data-driven world
Hanwha Power Systems and PSM unite as Hanwha Power, a global compresso...
NOAH HOLDINGS LIMITED ANNOUNCES UNAUDITED FINANCIAL RESULTS FOR THE FO...
YY Group (NASDAQ: YYGH) Appoints Arros AI Co-Founder Kai Yang as Chief...
vivo at Boao Forum: Building a Perception System Driven by “Imag...
GFTN, The University of Western Australia’s QUISA Research Centr...
LOGIN REGISTER
DigiconAsia
  • Features
    • Featured

      The rise of situational intelligence

      The rise of situational intelligence

      Thursday, March 19, 2026, 10:55 AM Asia/Singapore | Features
    • Featured

      Balancing brand heritage and modern service with AI-powered customer experience

      Balancing brand heritage and modern service with AI-powered customer experience

      Wednesday, March 18, 2026, 9:51 AM Asia/Singapore | Case Studies, Customer Experience, Features
    • Featured

      IoT trends APAC enterprises cannot ignore in 2026

      IoT trends APAC enterprises cannot ignore in 2026

      Friday, March 13, 2026, 3:02 PM Asia/Singapore | Features
  • News
    • Featured

      The New Straits Times adopts generative AI to improve news access, reader engagement

      The New Straits Times adopts generative AI to improve news access, reader engagement

      Tuesday, March 24, 2026, 4:48 PM Asia/Singapore | News, Newsletter
    • Featured

      AI agent misstep exposes sensitive data for two hours

      AI agent misstep exposes sensitive data for two hours

      Tuesday, March 24, 2026, 10:26 AM Asia/Singapore | News, Newsletter
    • Featured

      Look forward to less-aggressive AI updates in Windows amid widespread criticism and privacy concerns

      Look forward to less-aggressive AI updates in Windows amid widespread criticism and privacy concerns

      Monday, March 23, 2026, 9:24 AM Asia/Singapore | News
  • Perspectives
  • Tips & Strategies
  • Whitepapers
  • Awards 2023
  • Directory
  • E-Learning

Select Page

News

Critical remote code execution flaws uncovered in major AI inference frameworks

By DigiconAsia Editors | Monday, November 17, 2025, 4:11 PM Asia/Singapore

Critical remote code execution flaws uncovered in major AI inference frameworks

Security researchers reveal widespread vulnerabilities in AI frameworks due to unsafe coding and code reuse.

A series of critical remote code execution vulnerabilities have been discovered in major AI inference frameworks, exposing systems built by big tech AI firms to severe cyber risks.

The flaws, uncovered by Oligo Security researchers, demonstrate the far-reaching consequences of unsafe coding patterns and code reuse across open-source and proprietary AI projects.​

At the heart of the issue is a pattern named “ShadowMQ”, centered around the unsafe use of the ZeroMQ messaging library’s “recv_pyobj()” method in conjunction with Python’s pickle deserialization module.

Originally identified in Meta’s Llama large language model framework (CVE-2024-50050), the vulnerability allows attackers to remotely execute arbitrary code on exposed inference servers by sending malicious data through networked sockets. The exploit could lead to a total system takeover, data theft, or the insertion of unauthorized code, such as cryptocurrency miners or backdoors.​

Not an isolated risk
The problem is especially far-reaching because the same insecure pattern is found across several widely used frameworks. Oligo’s Avi Lumelsky has highlighted that identical unsafe code was routinely copied, often verbatim, from one project to another, spreading the flaw throughout the AI software supply chain.​

Each major implementation has now received a distinct CVE identifier:

  • NVIDIA’s TensorRT-LLM was assigned CVE-2025-23254 (CVSS 8.8), patched in version 0.18.2.
  • vLLM was flagged with CVE-2025-30165 (CVSS 8.0), though its older V0 engine remains vulnerable.
  • Modular Max Server’s version was fixed following disclosure (CVE-2025-60455).
  • Meta’s Llama-stack received CVE-2024-50050 and a critical CVSS of 9.3; the company replaced the risky deserialization with a type-safe JSON implementation in version 0.0.41.
  • Microsoft’s Sarathi-Serve remains unpatched as of this writing, and SGLang has yet to implement a complete fix.​

The research also extends beyond lab scenarios. The team reportedly found thousands of exposed ZeroMQ sockets on the public internet, a number of which connected to vulnerable AI inference clusters. If compromised, these weaknesses could allow initial attackers to move laterally across newly infected AI clusters, escalating attacks throughout entire deployments.​The incident highlights the cybersecurity risks of code reuse without rigorous review, especially in the fast-moving AI landscape.

Share:

PreviousRegional survey shows strong AI adoption but mixed maturity in developer workflows
NextCQG and Webull Singapore Partner to Bring Powerful Technology to the Broker’s New Futures Trading Offering

Related Posts

How to tackle the insatiable demands on data centers while ensuring sustainability

How to tackle the insatiable demands on data centers while ensuring sustainability

December 3, 2024

Global coral reefs face widespread die-off as Earth crosses the ecological Rubicon

Global coral reefs face widespread die-off as Earth crosses the ecological Rubicon

October 15, 2025

Pulling off a blockchain milestone in the Asian Digital bond market

Pulling off a blockchain milestone in the Asian Digital bond market

September 2, 2020

Understanding how leaders in data innovation achieve better business outcomes

Understanding how leaders in data innovation achieve better business outcomes

October 19, 2022

Leave a reply Cancel reply

You must be logged in to post a comment.

Awards Nomination Banner

gamification list

PARTICIPATE NOW

top placement

Whitepapers

  • Achieve Modernization Without the Complexity

    Achieve Modernization Without the Complexity

    Transforming IT infrastructure is crucial …Download Whitepaper
  • 5 Steps to Boost IT Infrastructure Reliability

    5 Steps to Boost IT Infrastructure Reliability

    In today's fast-evolving tech landscape, …Download Whitepaper
  • Simplify Payroll Setup for Your Small Business

    Simplify Payroll Setup for Your Small Business

    In our free guide, "How …Download Whitepaper
  • Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Download Whitepaper

Middle Placement

Case Studies

  • Balancing brand heritage and modern service with AI-powered customer experience

    Balancing brand heritage and modern service with AI-powered customer experience

    Balancing brand heritage and modern …Read More
  • Overhauling IT boosts business sustainability, efficiency amid motorsport carbon pressures: McLaren

    Overhauling IT boosts business sustainability, efficiency amid motorsport carbon pressures: McLaren

    The firm’s global IT team …Read More
  • Nokia integrates all-flash data infrastructure into telco cloud for network modernization

    Nokia integrates all-flash data infrastructure into telco cloud for network modernization

    Its December 2025 upgrade supports …Read More
  • Overcoming workforce challenges in Japan’s healthcare sector with generative AI: JCHO Osaka Hospital

    Overcoming workforce challenges in Japan’s healthcare sector with generative AI: JCHO Osaka Hospital

    A digitalization initiative launching by …Read More

Bottom Sidebar

Other News

  • Hanwha Power Systems and PSM unite as Hanwha Power, a global compressor and gas turbine business

    March 25, 2026
    The combined company will accelerate …Read More »
  • NOAH HOLDINGS LIMITED ANNOUNCES UNAUDITED FINANCIAL RESULTS FOR THE FOURTH QUARTER 2025 AND UNAUDITED FINANCIAL RESULTS FOR FULL YEAR 2025

    March 25, 2026
    SHANGHAI, March 25, 2026 /PRNewswire/ …Read More »
  • YY Group (NASDAQ: YYGH) Appoints Arros AI Co-Founder Kai Yang as Chief AI Scientist to Accelerate AI-Powered Workforce Platform Development

    March 25, 2026
    Appointment Deepens the Company’s AI …Read More »
  • vivo at Boao Forum: Building a Perception System Driven by “Imaging + AI”

    March 25, 2026
    BOAO, China, March 25, 2026 …Read More »
  • GFTN, The University of Western Australia’s QUISA Research Centre, and ST Engineering Partner to Advance Quantum-Safe Financial Infrastructure through Q-FINEX

    March 24, 2026
    PERTH, Australia, March 24, 2026 …Read More »
  • Our Brands
  • CybersecAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 DigiconAsia All Rights Reserved.