RECENT STORIES:

Addressing digital sovereignty in a data-driven world
Critical remote code execution flaws uncovered in major AI inference f...
Regional survey shows strong AI adoption but mixed maturity in develop...
Emirates Flight Catering unifies global operations with AI-driven data...
Mentor List Empowers Future Board Leaders with BCI Acquisition
HyperStrong and CATL Sign a Ten-year Agreement, Deepening Strategic Pa...
LOGIN REGISTER
DigiconAsia
  • Features
    • Featured

      How AI-driven discovery and social commerce are reshaping Singles Day 2025

      How AI-driven discovery and social commerce are reshaping Singles Day 2025

      Tuesday, November 11, 2025, 8:32 AM Asia/Singapore | e-Commerce, Features
    • Featured

      How useful is synthetic research and synthetic data?

      How useful is synthetic research and synthetic data?

      Wednesday, November 5, 2025, 2:52 PM Asia/Singapore | Features, Newsletter
    • Featured

      Leveraging CRM platform for AI-powered financial inclusion in Asia

      Leveraging CRM platform for AI-powered financial inclusion in Asia

      Friday, October 17, 2025, 2:34 PM Asia/Singapore | Features
  • News
    • Featured

      Critical remote code execution flaws uncovered in major AI inference frameworks

      Critical remote code execution flaws uncovered in major AI inference frameworks

      Monday, November 17, 2025, 4:11 PM Asia/Singapore | News, Newsletter
    • Featured

      Regional survey shows strong AI adoption but mixed maturity in developer workflows

      Regional survey shows strong AI adoption but mixed maturity in developer workflows

      Monday, November 17, 2025, 3:58 PM Asia/Singapore | News, Newsletter
    • Featured

      Emirates Flight Catering unifies global operations with AI-driven data governance and cloud collaboration

      Emirates Flight Catering unifies global operations with AI-driven data governance and cloud collaboration

      Monday, November 17, 2025, 10:33 AM Asia/Singapore | Case Studies, News
  • Perspectives
  • Tips & Strategies
  • Whitepapers
  • Awards 2023
  • Directory
  • E-Learning

Select Page

News

Critical remote code execution flaws uncovered in major AI inference frameworks

By DigiconAsia Editors | Monday, November 17, 2025, 4:11 PM Asia/Singapore

Critical remote code execution flaws uncovered in major AI inference frameworks

Security researchers reveal widespread vulnerabilities in AI frameworks due to unsafe coding and code reuse.

A series of critical remote code execution vulnerabilities have been discovered in major AI inference frameworks, exposing systems built by big tech AI firms to severe cyber risks.

The flaws, uncovered by Oligo Security researchers, demonstrate the far-reaching consequences of unsafe coding patterns and code reuse across open-source and proprietary AI projects.​

At the heart of the issue is a pattern named “ShadowMQ”, centered around the unsafe use of the ZeroMQ messaging library’s “recv_pyobj()” method in conjunction with Python’s pickle deserialization module.

Originally identified in Meta’s Llama large language model framework (CVE-2024-50050), the vulnerability allows attackers to remotely execute arbitrary code on exposed inference servers by sending malicious data through networked sockets. The exploit could lead to a total system takeover, data theft, or the insertion of unauthorized code, such as cryptocurrency miners or backdoors.​

Not an isolated risk
The problem is especially far-reaching because the same insecure pattern is found across several widely used frameworks. Oligo’s Avi Lumelsky has highlighted that identical unsafe code was routinely copied, often verbatim, from one project to another, spreading the flaw throughout the AI software supply chain.​

Each major implementation has now received a distinct CVE identifier:

  • NVIDIA’s TensorRT-LLM was assigned CVE-2025-23254 (CVSS 8.8), patched in version 0.18.2.
  • vLLM was flagged with CVE-2025-30165 (CVSS 8.0), though its older V0 engine remains vulnerable.
  • Modular Max Server’s version was fixed following disclosure (CVE-2025-60455).
  • Meta’s Llama-stack received CVE-2024-50050 and a critical CVSS of 9.3; the company replaced the risky deserialization with a type-safe JSON implementation in version 0.0.41.
  • Microsoft’s Sarathi-Serve remains unpatched as of this writing, and SGLang has yet to implement a complete fix.​

The research also extends beyond lab scenarios. The team reportedly found thousands of exposed ZeroMQ sockets on the public internet, a number of which connected to vulnerable AI inference clusters. If compromised, these weaknesses could allow initial attackers to move laterally across newly infected AI clusters, escalating attacks throughout entire deployments.​The incident highlights the cybersecurity risks of code reuse without rigorous review, especially in the fast-moving AI landscape.

Share:

PreviousRegional survey shows strong AI adoption but mixed maturity in developer workflows

Related Posts

Hybrid or hyflex? Collaborative learning technology is facilitating better online education either way

Hybrid or hyflex? Collaborative learning technology is facilitating better online education either way

September 16, 2022

Singapore self-help mobile app brings better health management to Taiwan

Singapore self-help mobile app brings better health management to Taiwan

October 30, 2019

Are your AI recruitment processes hiring automatons or diverse talent?

Are your AI recruitment processes hiring automatons or diverse talent?

December 20, 2021

Taming the data tsunami

Taming the data tsunami

May 21, 2021

Leave a reply Cancel reply

You must be logged in to post a comment.

Awards Nomination Banner

gamification list

PARTICIPATE NOW

top placement

Whitepapers

  • Achieve Modernization Without the Complexity

    Achieve Modernization Without the Complexity

    Transforming IT infrastructure is crucial …Download Whitepaper
  • 5 Steps to Boost IT Infrastructure Reliability

    5 Steps to Boost IT Infrastructure Reliability

    In today's fast-evolving tech landscape, …Download Whitepaper
  • Simplify Payroll Setup for Your Small Business

    Simplify Payroll Setup for Your Small Business

    In our free guide, "How …Download Whitepaper
  • Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Download Whitepaper

Middle Placement

Case Studies

  • Emirates Flight Catering unifies global operations with AI-driven data governance and cloud collaboration

    Emirates Flight Catering unifies global operations with AI-driven data governance and cloud collaboration

    The in-flight caterer modernizes data …Read More
  • Mergers and acquisitions drive urgent need for IT infrastructure overhaul: Access Group

    Mergers and acquisitions drive urgent need for IT infrastructure overhaul: Access Group

    Standardizing disparate enterprise-data infrastructures and …Read More
  • DIS recognized for driving open-source excellence in Singapore’s defense

    DIS recognized for driving open-source excellence in Singapore’s defense

    The Digital and Intelligence Service …Read More
  • Krom Bank renews cloud banking platform partnership to scale digital services in Indonesia

    Krom Bank renews cloud banking platform partnership to scale digital services in Indonesia

    The Indonesian digital bank will …Read More

Bottom Sidebar

Other News

  • Mentor List Empowers Future Board Leaders with BCI Acquisition

    November 17, 2025
    Strategic acquisition expands Mentor List’s …Read More »
  • HyperStrong and CATL Sign a Ten-year Agreement, Deepening Strategic Partnership Including 200 GWh Procurement Over Three Years

    November 17, 2025
    BEIJING, Nov. 17, 2025 /PRNewswire/ …Read More »
  • Galbot Unveils Dual Breakthroughs in Embodied AI: DexNDM and NavFoM Revolutionize Dexterous Manipulation and Autonomous Navigation

    November 16, 2025
    BEIJING, Nov. 16, 2025 /PRNewswire/ …Read More »
  • MicroCloud Hologram Inc. Releases Next-Generation Quantum Convolutional Neural Network Multi-Class Classification Technology, Driving Quantum Machine Learning Towards Practicalization

    November 15, 2025
    SHENZHEN, China, Nov. 15, 2025 …Read More »
  • PhotonPay Honored with Adam Smith Awards for FX Solution Innovation, Reshaping the Future of Global Currency Management

    November 14, 2025
    HONG KONG, Nov. 14, 2025 …Read More »
  • Our Brands
  • CybersecAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2025 DigiconAsia All Rights Reserved.