RECENT STORIES:

Addressing digital sovereignty in a data-driven world
China authorities pause robotaxi licenses after unexplained Wuhan vehi...
Coway Listed in the 2026 S&P Sustainability Yearbook and Dow Jones...
SM Q1 net income grows 7% to PHP21.5 billion
Eason Technology Limited Filed Annual Report on Form 20-F for Fiscal Y...
Cathay Financial Holdings Extends Streak on Dow Jones’ Best-in-C...
LOGIN REGISTER
DigiconAsia
  • Features
    • Featured

      The double-edged knife that boomeranged: Warnings about AI comes alive in one executive’s ruin

      The double-edged knife that boomeranged: Warnings about AI comes alive in one executive’s ruin

      Monday, April 27, 2026, 10:56 AM Asia/Singapore | Features, Newsletter
    • Featured

      Is educational technology in Asian primary schools evolving with the AI impact?

      Is educational technology in Asian primary schools evolving with the AI impact?

      Thursday, March 26, 2026, 2:02 PM Asia/Singapore | Features
    • Featured

      The rise of situational intelligence

      The rise of situational intelligence

      Thursday, March 19, 2026, 10:55 AM Asia/Singapore | Features
  • News
    • Featured

      Discovery of self-organizing laser beam in optical fiber slated to enhance brain imaging tech

      Discovery of self-organizing laser beam in optical fiber slated to enhance brain imaging tech

      Thursday, April 30, 2026, 10:51 AM Asia/Singapore | News
    • Featured

      Liverpool FC to deliver more personalized, real-time digital fan experiences with AI

      Liverpool FC to deliver more personalized, real-time digital fan experiences with AI

      Wednesday, April 29, 2026, 10:39 AM Asia/Singapore | Case Studies, News
    • Featured

      How have AI agents in four ASEAN economies amid uneven training and evolving roles?

      How have AI agents in four ASEAN economies amid uneven training and evolving roles?

      Wednesday, April 29, 2026, 10:36 AM Asia/Singapore | News
  • Perspectives
  • Tips & Strategies
  • Whitepapers
  • Directory
  • E-Learning

Select Page

News

Critical remote code execution flaws uncovered in major AI inference frameworks

By DigiconAsia Editors | Monday, November 17, 2025, 4:11 PM Asia/Singapore

Critical remote code execution flaws uncovered in major AI inference frameworks

Security researchers reveal widespread vulnerabilities in AI frameworks due to unsafe coding and code reuse.

A series of critical remote code execution vulnerabilities have been discovered in major AI inference frameworks, exposing systems built by big tech AI firms to severe cyber risks.

The flaws, uncovered by Oligo Security researchers, demonstrate the far-reaching consequences of unsafe coding patterns and code reuse across open-source and proprietary AI projects.​

At the heart of the issue is a pattern named “ShadowMQ”, centered around the unsafe use of the ZeroMQ messaging library’s “recv_pyobj()” method in conjunction with Python’s pickle deserialization module.

Originally identified in Meta’s Llama large language model framework (CVE-2024-50050), the vulnerability allows attackers to remotely execute arbitrary code on exposed inference servers by sending malicious data through networked sockets. The exploit could lead to a total system takeover, data theft, or the insertion of unauthorized code, such as cryptocurrency miners or backdoors.​

Not an isolated risk
The problem is especially far-reaching because the same insecure pattern is found across several widely used frameworks. Oligo’s Avi Lumelsky has highlighted that identical unsafe code was routinely copied, often verbatim, from one project to another, spreading the flaw throughout the AI software supply chain.​

Each major implementation has now received a distinct CVE identifier:

  • NVIDIA’s TensorRT-LLM was assigned CVE-2025-23254 (CVSS 8.8), patched in version 0.18.2.
  • vLLM was flagged with CVE-2025-30165 (CVSS 8.0), though its older V0 engine remains vulnerable.
  • Modular Max Server’s version was fixed following disclosure (CVE-2025-60455).
  • Meta’s Llama-stack received CVE-2024-50050 and a critical CVSS of 9.3; the company replaced the risky deserialization with a type-safe JSON implementation in version 0.0.41.
  • Microsoft’s Sarathi-Serve remains unpatched as of this writing, and SGLang has yet to implement a complete fix.​

The research also extends beyond lab scenarios. The team reportedly found thousands of exposed ZeroMQ sockets on the public internet, a number of which connected to vulnerable AI inference clusters. If compromised, these weaknesses could allow initial attackers to move laterally across newly infected AI clusters, escalating attacks throughout entire deployments.​The incident highlights the cybersecurity risks of code reuse without rigorous review, especially in the fast-moving AI landscape.

Share:

PreviousRegional survey shows strong AI adoption but mixed maturity in developer workflows
NextCQG and Webull Singapore Partner to Bring Powerful Technology to the Broker’s New Futures Trading Offering

Related Posts

Does your disaster recovery plan resume operations under 12 hours?

Does your disaster recovery plan resume operations under 12 hours?

September 19, 2022

The AI race continues: China-made processors cut training costs by 20%

The AI race continues: China-made processors cut training costs by 20%

March 26, 2025

What successful digitalization is really about

What successful digitalization is really about

August 11, 2020

Making a mix of peas, seeds and brown rice taste like chicken meat

Making a mix of peas, seeds and brown rice taste like chicken meat

November 28, 2022

Leave a reply Cancel reply

You must be logged in to post a comment.

Awards Nomination Banner

gamification list

PARTICIPATE NOW

top placement

Whitepapers

  • Achieve Modernization Without the Complexity

    Achieve Modernization Without the Complexity

    Transforming IT infrastructure is crucial …Download Whitepaper
  • 5 Steps to Boost IT Infrastructure Reliability

    5 Steps to Boost IT Infrastructure Reliability

    In today's fast-evolving tech landscape, …Download Whitepaper
  • Simplify Payroll Setup for Your Small Business

    Simplify Payroll Setup for Your Small Business

    In our free guide, "How …Download Whitepaper
  • Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Download Whitepaper

Middle Placement

Case Studies

  • Liverpool FC to deliver more personalized, real-time digital fan experiences with AI

    Liverpool FC to deliver more personalized, real-time digital fan experiences with AI

    The football club will deepen …Read More
  • Balancing brand heritage and modern service with AI-powered customer experience

    Balancing brand heritage and modern service with AI-powered customer experience

    Balancing brand heritage and modern …Read More
  • Overhauling IT boosts business sustainability, efficiency amid motorsport carbon pressures: McLaren

    Overhauling IT boosts business sustainability, efficiency amid motorsport carbon pressures: McLaren

    The firm’s global IT team …Read More
  • Nokia integrates all-flash data infrastructure into telco cloud for network modernization

    Nokia integrates all-flash data infrastructure into telco cloud for network modernization

    Its December 2025 upgrade supports …Read More

Bottom Sidebar

Other News

  • Coway Listed in the 2026 S&P Sustainability Yearbook and Dow Jones Best-in-Class Asia Pacific Index

    May 5, 2026
    Coway has been ranked in …Read More »
  • SM Q1 net income grows 7% to PHP21.5 billion

    May 5, 2026
    PASAY CITY, Philippines, May 4, …Read More »
  • Eason Technology Limited Filed Annual Report on Form 20-F for Fiscal Year 2025

    May 5, 2026
    HONG KONG, May 5, 2026 …Read More »
  • Cathay Financial Holdings Extends Streak on Dow Jones’ Best-in-Class World Index, and Emerging Markets Index

    May 4, 2026
    Its ESG Score ranks in …Read More »
  • AMRO Marks 10 Years as an International Organization

    May 4, 2026
    Director/CEO Yasuto Watanabe reaffirms commitment …Read More »
  • Our Brands
  • CybersecAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 DigiconAsia All Rights Reserved.