RECENT STORIES:

Addressing digital sovereignty in a data-driven world
ARC Group Brings the Premier Capital Markets & M&A Forum to To...
Taoping Announces Transformational Growth Milestones: New Corporate He...
Shenzhou Machinery Launches Cold-Resistant Industrial Centrifuges at E...
ECOPEACE Accelerates Global Deployment of AI-Driven Water-Cleanup Tech...
RKTech Invests in Entropy, Unlocking Access to Two Million LATAM Techn...
LOGIN REGISTER
DigiconAsia
  • Features
    • Featured

      Low-code platform enables digital-first agility

      Low-code platform enables digital-first agility

      Friday, December 26, 2025, 1:38 AM Asia/Singapore | Case Studies, Features
    • Featured

      Agents of change – the future of AI-powered e-commerce

      Agents of change – the future of AI-powered e-commerce

      Wednesday, December 24, 2025, 1:22 PM Asia/Singapore | e-Commerce, Features
    • Featured

      Time to rethink the real impact of AI on work productivity in 2026?

      Time to rethink the real impact of AI on work productivity in 2026?

      Thursday, December 18, 2025, 2:43 PM Asia/Singapore | Features
  • News
    • Featured

      Creator of AI coding super tool warns against full reliance on vibe coding

      Creator of AI coding super tool warns against full reliance on vibe coding

      Thursday, December 18, 2025, 10:11 AM Asia/Singapore | News, Newsletter
    • Featured

      AI chatbots excel at political persuasion yet sacrifice accuracy: landmark study

      AI chatbots excel at political persuasion yet sacrifice accuracy: landmark study

      Wednesday, December 17, 2025, 10:21 AM Asia/Singapore | News, Newsletter
    • Featured

      South Korea to enforce world’s first comprehensive AI law ahead of European Union

      South Korea to enforce world’s first comprehensive AI law ahead of European Union

      Tuesday, December 16, 2025, 11:10 AM Asia/Singapore | News, Newsletter
  • Perspectives
  • Tips & Strategies
  • Whitepapers
  • Awards 2023
  • Directory
  • E-Learning

Select Page

News

Critical remote code execution flaws uncovered in major AI inference frameworks

By DigiconAsia Editors | Monday, November 17, 2025, 4:11 PM Asia/Singapore

Critical remote code execution flaws uncovered in major AI inference frameworks

Security researchers reveal widespread vulnerabilities in AI frameworks due to unsafe coding and code reuse.

A series of critical remote code execution vulnerabilities have been discovered in major AI inference frameworks, exposing systems built by big tech AI firms to severe cyber risks.

The flaws, uncovered by Oligo Security researchers, demonstrate the far-reaching consequences of unsafe coding patterns and code reuse across open-source and proprietary AI projects.​

At the heart of the issue is a pattern named “ShadowMQ”, centered around the unsafe use of the ZeroMQ messaging library’s “recv_pyobj()” method in conjunction with Python’s pickle deserialization module.

Originally identified in Meta’s Llama large language model framework (CVE-2024-50050), the vulnerability allows attackers to remotely execute arbitrary code on exposed inference servers by sending malicious data through networked sockets. The exploit could lead to a total system takeover, data theft, or the insertion of unauthorized code, such as cryptocurrency miners or backdoors.​

Not an isolated risk
The problem is especially far-reaching because the same insecure pattern is found across several widely used frameworks. Oligo’s Avi Lumelsky has highlighted that identical unsafe code was routinely copied, often verbatim, from one project to another, spreading the flaw throughout the AI software supply chain.​

Each major implementation has now received a distinct CVE identifier:

  • NVIDIA’s TensorRT-LLM was assigned CVE-2025-23254 (CVSS 8.8), patched in version 0.18.2.
  • vLLM was flagged with CVE-2025-30165 (CVSS 8.0), though its older V0 engine remains vulnerable.
  • Modular Max Server’s version was fixed following disclosure (CVE-2025-60455).
  • Meta’s Llama-stack received CVE-2024-50050 and a critical CVSS of 9.3; the company replaced the risky deserialization with a type-safe JSON implementation in version 0.0.41.
  • Microsoft’s Sarathi-Serve remains unpatched as of this writing, and SGLang has yet to implement a complete fix.​

The research also extends beyond lab scenarios. The team reportedly found thousands of exposed ZeroMQ sockets on the public internet, a number of which connected to vulnerable AI inference clusters. If compromised, these weaknesses could allow initial attackers to move laterally across newly infected AI clusters, escalating attacks throughout entire deployments.​The incident highlights the cybersecurity risks of code reuse without rigorous review, especially in the fast-moving AI landscape.

Share:

PreviousRegional survey shows strong AI adoption but mixed maturity in developer workflows
NextCQG and Webull Singapore Partner to Bring Powerful Technology to the Broker’s New Futures Trading Offering

Related Posts

India’s tech-averse food industry finally acclimatizing to the Cloud

India’s tech-averse food industry finally acclimatizing to the Cloud

May 11, 2022

First-ever digital platform set to ease working-capital strains for construction contractors

First-ever digital platform set to ease working-capital strains for construction contractors

November 22, 2023

What enterprise IT can learn from the app store concept

What enterprise IT can learn from the app store concept

June 18, 2020

German auto maker targets unveiling of ‘software defined vehicles’ by 2025

German auto maker targets unveiling of ‘software defined vehicles’ by 2025

July 8, 2022

Leave a reply Cancel reply

You must be logged in to post a comment.

Awards Nomination Banner

gamification list

PARTICIPATE NOW

top placement

Whitepapers

  • Achieve Modernization Without the Complexity

    Achieve Modernization Without the Complexity

    Transforming IT infrastructure is crucial …Download Whitepaper
  • 5 Steps to Boost IT Infrastructure Reliability

    5 Steps to Boost IT Infrastructure Reliability

    In today's fast-evolving tech landscape, …Download Whitepaper
  • Simplify Payroll Setup for Your Small Business

    Simplify Payroll Setup for Your Small Business

    In our free guide, "How …Download Whitepaper
  • Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Download Whitepaper

Middle Placement

Case Studies

  • Low-code platform enables digital-first agility

    Low-code platform enables digital-first agility

    Few industries demand agility and …Read More
  • Going green all the way to Cyberjaya: Labuan Reinsurance’s data center relocation

    Going green all the way to Cyberjaya: Labuan Reinsurance’s data center relocation

    Relocation boosts sustainability, while a …Read More
  • When traditional intelligent business automation hits a roadblock, try AI agents

    When traditional intelligent business automation hits a roadblock, try AI agents

    That is what the Langham …Read More
  • CTBC defines future of transition finance with Evercomm solution

    CTBC defines future of transition finance with Evercomm solution

    Taiwanese bank leverages Evercomm’s AI-powered …Read More

Bottom Sidebar

Other News

  • ARC Group Brings the Premier Capital Markets & M&A Forum to Tokyo

    December 30, 2025
    TOKYO, Dec. 29, 2025 /PRNewswire/ …Read More »
  • Taoping Announces Transformational Growth Milestones: New Corporate Headquarters and US$2 Million Smart Infrastructure Contracts

    December 29, 2025
    TIANJIN, China, Dec. 29, 2025 …Read More »
  • Shenzhou Machinery Launches Cold-Resistant Industrial Centrifuges at ECWATECH 2025 in Moscow, Accelerates Expansion in Eastern Europe

    December 29, 2025
    JINHUA, China, Dec. 29, 2025 …Read More »
  • ECOPEACE Accelerates Global Deployment of AI-Driven Water-Cleanup Technology in Singapore and Dubai

    December 29, 2025
    South Korean water-tech innovator advances …Read More »
  • RKTech Invests in Entropy, Unlocking Access to Two Million LATAM Technology Professionals

    December 27, 2025
    DALLAS, Dec. 27, 2025 /PRNewswire/ …Read More »
  • Our Brands
  • CybersecAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2025 DigiconAsia All Rights Reserved.