RECENT STORIES:

Addressing digital sovereignty in a data-driven world
MicroCloud Hologram Inc. Releases Hybrid Quantum-Classical Three-Dimen...
LGHL ANNOUNCES THAT ITS WHOLLY-OWNED SUBSIDIARY HAS BEEN GRANTED EXCLU...
STAK Inc. Regains Compliance with Nasdaq Bid Price Requirement
Full Truck Alliance Co. Ltd. Files 2025 Annual Report on Form 20-F
Tencent Music Entertainment Group to Report First Quarter 2026 Financi...
LOGIN REGISTER
DigiconAsia
  • Features
    • Featured

      Is educational technology in Asian primary schools evolving with the AI impact?

      Is educational technology in Asian primary schools evolving with the AI impact?

      Thursday, March 26, 2026, 2:02 PM Asia/Singapore | Features
    • Featured

      The rise of situational intelligence

      The rise of situational intelligence

      Thursday, March 19, 2026, 10:55 AM Asia/Singapore | Features
    • Featured

      Balancing brand heritage and modern service with AI-powered customer experience

      Balancing brand heritage and modern service with AI-powered customer experience

      Wednesday, March 18, 2026, 9:51 AM Asia/Singapore | Case Studies, Customer Experience, Features
  • News
    • Featured

      US envoy urges EU to ease tech regulation for AI competitiveness

      US envoy urges EU to ease tech regulation for AI competitiveness

      Monday, April 13, 2026, 5:28 PM Asia/Singapore | e-Commerce, News
    • Featured

      Global cloud outage from one firm disrupts services, renewing concerns over infrastructure reliability

      Global cloud outage from one firm disrupts services, renewing concerns over infrastructure reliability

      Monday, April 13, 2026, 2:49 PM Asia/Singapore | News, Newsletter
    • Featured

      Unshackling from vendor support lock-in to improve ongoing digitization: Lotte Rental

      Unshackling from vendor support lock-in to improve ongoing digitization: Lotte Rental

      Friday, April 10, 2026, 10:33 AM Asia/Singapore | News
  • Perspectives
  • Tips & Strategies
  • Whitepapers
  • Directory
  • E-Learning

Select Page

News

Critical remote code execution flaws uncovered in major AI inference frameworks

By DigiconAsia Editors | Monday, November 17, 2025, 4:11 PM Asia/Singapore

Critical remote code execution flaws uncovered in major AI inference frameworks

Security researchers reveal widespread vulnerabilities in AI frameworks due to unsafe coding and code reuse.

A series of critical remote code execution vulnerabilities have been discovered in major AI inference frameworks, exposing systems built by big tech AI firms to severe cyber risks.

The flaws, uncovered by Oligo Security researchers, demonstrate the far-reaching consequences of unsafe coding patterns and code reuse across open-source and proprietary AI projects.​

At the heart of the issue is a pattern named “ShadowMQ”, centered around the unsafe use of the ZeroMQ messaging library’s “recv_pyobj()” method in conjunction with Python’s pickle deserialization module.

Originally identified in Meta’s Llama large language model framework (CVE-2024-50050), the vulnerability allows attackers to remotely execute arbitrary code on exposed inference servers by sending malicious data through networked sockets. The exploit could lead to a total system takeover, data theft, or the insertion of unauthorized code, such as cryptocurrency miners or backdoors.​

Not an isolated risk
The problem is especially far-reaching because the same insecure pattern is found across several widely used frameworks. Oligo’s Avi Lumelsky has highlighted that identical unsafe code was routinely copied, often verbatim, from one project to another, spreading the flaw throughout the AI software supply chain.​

Each major implementation has now received a distinct CVE identifier:

  • NVIDIA’s TensorRT-LLM was assigned CVE-2025-23254 (CVSS 8.8), patched in version 0.18.2.
  • vLLM was flagged with CVE-2025-30165 (CVSS 8.0), though its older V0 engine remains vulnerable.
  • Modular Max Server’s version was fixed following disclosure (CVE-2025-60455).
  • Meta’s Llama-stack received CVE-2024-50050 and a critical CVSS of 9.3; the company replaced the risky deserialization with a type-safe JSON implementation in version 0.0.41.
  • Microsoft’s Sarathi-Serve remains unpatched as of this writing, and SGLang has yet to implement a complete fix.​

The research also extends beyond lab scenarios. The team reportedly found thousands of exposed ZeroMQ sockets on the public internet, a number of which connected to vulnerable AI inference clusters. If compromised, these weaknesses could allow initial attackers to move laterally across newly infected AI clusters, escalating attacks throughout entire deployments.​The incident highlights the cybersecurity risks of code reuse without rigorous review, especially in the fast-moving AI landscape.

Share:

PreviousRegional survey shows strong AI adoption but mixed maturity in developer workflows
NextCQG and Webull Singapore Partner to Bring Powerful Technology to the Broker’s New Futures Trading Offering

Related Posts

Global Re expands into Dubai with automatic and analytics aforethought

Global Re expands into Dubai with automatic and analytics aforethought

December 11, 2023

How technology helps in designing sustainable smart cities

How technology helps in designing sustainable smart cities

August 23, 2021

Rapid growth of New Energy Vehicles market drove VW to the Cloud

Rapid growth of New Energy Vehicles market drove VW to the Cloud

September 22, 2023

Pilot scheme for blockchain-powered verifiable financial data kicks off

Pilot scheme for blockchain-powered verifiable financial data kicks off

October 20, 2023

Leave a reply Cancel reply

You must be logged in to post a comment.

Awards Nomination Banner

gamification list

PARTICIPATE NOW

top placement

Whitepapers

  • Achieve Modernization Without the Complexity

    Achieve Modernization Without the Complexity

    Transforming IT infrastructure is crucial …Download Whitepaper
  • 5 Steps to Boost IT Infrastructure Reliability

    5 Steps to Boost IT Infrastructure Reliability

    In today's fast-evolving tech landscape, …Download Whitepaper
  • Simplify Payroll Setup for Your Small Business

    Simplify Payroll Setup for Your Small Business

    In our free guide, "How …Download Whitepaper
  • Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Download Whitepaper

Middle Placement

Case Studies

  • Balancing brand heritage and modern service with AI-powered customer experience

    Balancing brand heritage and modern service with AI-powered customer experience

    Balancing brand heritage and modern …Read More
  • Overhauling IT boosts business sustainability, efficiency amid motorsport carbon pressures: McLaren

    Overhauling IT boosts business sustainability, efficiency amid motorsport carbon pressures: McLaren

    The firm’s global IT team …Read More
  • Nokia integrates all-flash data infrastructure into telco cloud for network modernization

    Nokia integrates all-flash data infrastructure into telco cloud for network modernization

    Its December 2025 upgrade supports …Read More
  • Overcoming workforce challenges in Japan’s healthcare sector with generative AI: JCHO Osaka Hospital

    Overcoming workforce challenges in Japan’s healthcare sector with generative AI: JCHO Osaka Hospital

    A digitalization initiative launching by …Read More

Bottom Sidebar

Other News

  • MicroCloud Hologram Inc. Releases Hybrid Quantum-Classical Three-Dimensional Object Technology for Multi-Channel Quantum Convolutional Neural Networks

    April 14, 2026
    SHENZHEN, China, April 14, 2026 …Read More »
  • LGHL ANNOUNCES THAT ITS WHOLLY-OWNED SUBSIDIARY HAS BEEN GRANTED EXCLUSIVITY TO FURTHER NEGOTIATIONS AND THE ENTERING INTO OF A FORMAL AGREEMENT IN RESPECT OF THE PROPOSED RESTRUCTURING OF SKYFAME REALTY (HOLDINGS) LIMITED (IN LIQUIDATION)

    April 14, 2026
    SINGAPORE, April 14, 2026 /PRNewswire/ …Read More »
  • STAK Inc. Regains Compliance with Nasdaq Bid Price Requirement

    April 14, 2026
    CHANGZHOU, China, April 14, 2026 …Read More »
  • Full Truck Alliance Co. Ltd. Files 2025 Annual Report on Form 20-F

    April 14, 2026
    GUIYANG, China, April 14, 2026 …Read More »
  • Tencent Music Entertainment Group to Report First Quarter 2026 Financial Results on May 12, 2026

    April 14, 2026
    SHENZHEN, China, April 14, 2026 …Read More »
  • Our Brands
  • CybersecAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 DigiconAsia All Rights Reserved.