RECENT STORIES:

Addressing digital sovereignty in a data-driven world
Guangzhou International Arbitration Court Opens Vietnam Liaison Office...
Navigating High Market Volatility: Insights from JustMarkets
GCL SI Showcases Scenario-Based PV Solutions at SNEC 2026, Driving App...
Cheche Group Announces Results of Extraordinary General Meeting
Dragonpass APAC Loyalty Index: 53% of High-Income Consumers Say Bank R...
LOGIN REGISTER
DigiconAsia
  • Features
    • Featured

      Bridging the gap from AI prototype to production

      Bridging the gap from AI prototype to production

      Wednesday, June 10, 2026, 1:53 PM Asia/Singapore | Features
    • Featured

      Data centers and the digital infrastructure crunch in Asia

      Data centers and the digital infrastructure crunch in Asia

      Monday, June 8, 2026, 3:02 PM Asia/Singapore | Features
    • Featured

      In AI missions, who governs the agents

      In AI missions, who governs the agents

      Thursday, June 4, 2026, 4:06 PM Asia/Singapore | Features
  • News
    • Featured

      Agent-based adtech tool converts briefs into structured audience definitions for unified planning, execution

      Agent-based adtech tool converts briefs into structured audience definitions for unified planning, execution

      Friday, June 12, 2026, 3:04 PM Asia/Singapore | News
    • Featured

      IP lawsuit could shape how uploaded content can be used for AI training

      IP lawsuit could shape how uploaded content can be used for AI training

      Friday, June 12, 2026, 1:24 PM Asia/Singapore | News
    • Featured

      Brain-controlled art and BCI – the future of creativity and accessibility?

      Brain-controlled art and BCI - the future of creativity and accessibility?

      Friday, June 12, 2026, 8:38 AM Asia/Singapore | News
  • Perspectives
  • Tips & Strategies
  • Whitepapers
  • Directory
  • E-Learning

Select Page

News

Critical remote code execution flaws uncovered in major AI inference frameworks

By DigiconAsia Editors | Monday, November 17, 2025, 4:11 PM Asia/Singapore

Critical remote code execution flaws uncovered in major AI inference frameworks

Security researchers reveal widespread vulnerabilities in AI frameworks due to unsafe coding and code reuse.

A series of critical remote code execution vulnerabilities have been discovered in major AI inference frameworks, exposing systems built by big tech AI firms to severe cyber risks.

The flaws, uncovered by Oligo Security researchers, demonstrate the far-reaching consequences of unsafe coding patterns and code reuse across open-source and proprietary AI projects.​

At the heart of the issue is a pattern named “ShadowMQ”, centered around the unsafe use of the ZeroMQ messaging library’s “recv_pyobj()” method in conjunction with Python’s pickle deserialization module.

Originally identified in Meta’s Llama large language model framework (CVE-2024-50050), the vulnerability allows attackers to remotely execute arbitrary code on exposed inference servers by sending malicious data through networked sockets. The exploit could lead to a total system takeover, data theft, or the insertion of unauthorized code, such as cryptocurrency miners or backdoors.​

Not an isolated risk
The problem is especially far-reaching because the same insecure pattern is found across several widely used frameworks. Oligo’s Avi Lumelsky has highlighted that identical unsafe code was routinely copied, often verbatim, from one project to another, spreading the flaw throughout the AI software supply chain.​

Each major implementation has now received a distinct CVE identifier:

  • NVIDIA’s TensorRT-LLM was assigned CVE-2025-23254 (CVSS 8.8), patched in version 0.18.2.
  • vLLM was flagged with CVE-2025-30165 (CVSS 8.0), though its older V0 engine remains vulnerable.
  • Modular Max Server’s version was fixed following disclosure (CVE-2025-60455).
  • Meta’s Llama-stack received CVE-2024-50050 and a critical CVSS of 9.3; the company replaced the risky deserialization with a type-safe JSON implementation in version 0.0.41.
  • Microsoft’s Sarathi-Serve remains unpatched as of this writing, and SGLang has yet to implement a complete fix.​

The research also extends beyond lab scenarios. The team reportedly found thousands of exposed ZeroMQ sockets on the public internet, a number of which connected to vulnerable AI inference clusters. If compromised, these weaknesses could allow initial attackers to move laterally across newly infected AI clusters, escalating attacks throughout entire deployments.​The incident highlights the cybersecurity risks of code reuse without rigorous review, especially in the fast-moving AI landscape.

Share:

PreviousRegional survey shows strong AI adoption but mixed maturity in developer workflows
NextCQG and Webull Singapore Partner to Bring Powerful Technology to the Broker’s New Futures Trading Offering

Related Posts

AI agent misstep exposes sensitive data for two hours

AI agent misstep exposes sensitive data for two hours

March 24, 2026

Explosive data centers growth in SE Asia: sustainability is the mandate

Explosive data centers growth in SE Asia: sustainability is the mandate

October 28, 2020

Mitsui OSK Lines leverages Intelligent Data Management Cloud to modernize core system

Mitsui OSK Lines leverages Intelligent Data Management Cloud to modernize core system

September 19, 2023

How travel-app users react to push notifications and marketing emails?

How travel-app users react to push notifications and marketing emails?

July 6, 2023

Leave a reply Cancel reply

You must be logged in to post a comment.

Awards Nomination Banner

gamification list

PARTICIPATE NOW

top placement

Whitepapers

  • Achieve Modernization Without the Complexity

    Achieve Modernization Without the Complexity

    Transforming IT infrastructure is crucial …Download Whitepaper
  • 5 Steps to Boost IT Infrastructure Reliability

    5 Steps to Boost IT Infrastructure Reliability

    In today's fast-evolving tech landscape, …Download Whitepaper
  • Simplify Payroll Setup for Your Small Business

    Simplify Payroll Setup for Your Small Business

    In our free guide, "How …Download Whitepaper
  • Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Download Whitepaper

Middle Placement

Case Studies

  • The 48-hour lifeline: How the IRC rewrote the rules for crisis care

    The 48-hour lifeline: How the IRC rewrote the rules for crisis care

    In a world where crises …Read More
  • CALB upgrades data platform to support analytics, security, and battery lifecycle tracking

    CALB upgrades data platform to support analytics, security, and battery lifecycle tracking

    Deploying a petabyte-scale data lake …Read More
  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your …Read More
  • Liverpool FC to deliver more personalized, real-time digital fan experiences with AI

    Liverpool FC to deliver more personalized, real-time digital fan experiences with AI

    The football club will deepen …Read More

Bottom Sidebar

Other News

  • Guangzhou International Arbitration Court Opens Vietnam Liaison Office to Support China-Vietnam Cross-Border Dispute Resolution

    June 13, 2026
    HO CHI MINH CITY, Vietnam, …Read More »
  • Navigating High Market Volatility: Insights from JustMarkets

    June 13, 2026
    HO CHI MINH CITY, Vietnam, …Read More »
  • GCL SI Showcases Scenario-Based PV Solutions at SNEC 2026, Driving Application-Specific Solar Deployment and Low-Carbon Development

    June 13, 2026
    SHANGHAI, June 12, 2026 /PRNewswire/ …Read More »
  • Cheche Group Announces Results of Extraordinary General Meeting

    June 12, 2026
    BEIJING, June 12, 2026 /PRNewswire/ …Read More »
  • Dragonpass APAC Loyalty Index: 53% of High-Income Consumers Say Bank Rewards No Longer Match Their Lifestyle Needs

    June 12, 2026
    SINGAPORE, June 12, 2026 /PRNewswire/ …Read More »
  • Our Brands
  • CybersecAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 DigiconAsia All Rights Reserved.