RECENT STORIES:

Addressing digital sovereignty in a data-driven world
IoT trends APAC enterprises cannot ignore in 2026
AI coding tools introduce security flaws in 87% of pull requests: repo...
CGTN AMERICA & CCTV UN: China in Springtime: China’s Develop...
VIVOTEK Accelerates AI Innovation Through Network Optix Platform Integ...
CLPS Incorporation Announces AI-Driven COBOL-to-Java Migration Solutio...
LOGIN REGISTER
DigiconAsia
  • Features
    • Featured

      IoT trends APAC enterprises cannot ignore in 2026

      IoT trends APAC enterprises cannot ignore in 2026

      Friday, March 13, 2026, 3:02 PM Asia/Singapore | Features
    • Featured

      AI-driven manufacturing can reshape South-east Asia amid skills, cost and security challenges

      AI-driven manufacturing can reshape South-east Asia amid skills, cost and security challenges

      Wednesday, March 11, 2026, 2:49 PM Asia/Singapore | Features, Newsletter
    • Featured

      How AI is reshaping dating in Asia

      How AI is reshaping dating in Asia

      Monday, February 9, 2026, 5:00 AM Asia/Singapore | Features, Newsletter
  • News
    • Featured

      AI coding tools introduce security flaws in 87% of pull requests: report

      AI coding tools introduce security flaws in 87% of pull requests: report

      Friday, March 13, 2026, 10:40 AM Asia/Singapore | News, Newsletter
    • Featured

      EU Parliament backs stricter copyright rules for generative AI training and creator compensation

      EU Parliament backs stricter copyright rules for generative AI training and creator compensation

      Thursday, March 12, 2026, 11:03 AM Asia/Singapore | News, Newsletter
    • Featured

      Pentagon labels US AI startup’s military-use restrictions as a “supply chain risk”

      Pentagon labels US AI startup’s military-use restrictions as a “supply chain risk”

      Wednesday, March 11, 2026, 1:51 PM Asia/Singapore | News, Newsletter
  • Perspectives
  • Tips & Strategies
  • Whitepapers
  • Awards 2023
  • Directory
  • E-Learning

Select Page

News

Critical remote code execution flaws uncovered in major AI inference frameworks

By DigiconAsia Editors | Monday, November 17, 2025, 4:11 PM Asia/Singapore

Critical remote code execution flaws uncovered in major AI inference frameworks

Security researchers reveal widespread vulnerabilities in AI frameworks due to unsafe coding and code reuse.

A series of critical remote code execution vulnerabilities have been discovered in major AI inference frameworks, exposing systems built by big tech AI firms to severe cyber risks.

The flaws, uncovered by Oligo Security researchers, demonstrate the far-reaching consequences of unsafe coding patterns and code reuse across open-source and proprietary AI projects.​

At the heart of the issue is a pattern named “ShadowMQ”, centered around the unsafe use of the ZeroMQ messaging library’s “recv_pyobj()” method in conjunction with Python’s pickle deserialization module.

Originally identified in Meta’s Llama large language model framework (CVE-2024-50050), the vulnerability allows attackers to remotely execute arbitrary code on exposed inference servers by sending malicious data through networked sockets. The exploit could lead to a total system takeover, data theft, or the insertion of unauthorized code, such as cryptocurrency miners or backdoors.​

Not an isolated risk
The problem is especially far-reaching because the same insecure pattern is found across several widely used frameworks. Oligo’s Avi Lumelsky has highlighted that identical unsafe code was routinely copied, often verbatim, from one project to another, spreading the flaw throughout the AI software supply chain.​

Each major implementation has now received a distinct CVE identifier:

  • NVIDIA’s TensorRT-LLM was assigned CVE-2025-23254 (CVSS 8.8), patched in version 0.18.2.
  • vLLM was flagged with CVE-2025-30165 (CVSS 8.0), though its older V0 engine remains vulnerable.
  • Modular Max Server’s version was fixed following disclosure (CVE-2025-60455).
  • Meta’s Llama-stack received CVE-2024-50050 and a critical CVSS of 9.3; the company replaced the risky deserialization with a type-safe JSON implementation in version 0.0.41.
  • Microsoft’s Sarathi-Serve remains unpatched as of this writing, and SGLang has yet to implement a complete fix.​

The research also extends beyond lab scenarios. The team reportedly found thousands of exposed ZeroMQ sockets on the public internet, a number of which connected to vulnerable AI inference clusters. If compromised, these weaknesses could allow initial attackers to move laterally across newly infected AI clusters, escalating attacks throughout entire deployments.​The incident highlights the cybersecurity risks of code reuse without rigorous review, especially in the fast-moving AI landscape.

Share:

PreviousRegional survey shows strong AI adoption but mixed maturity in developer workflows
NextCQG and Webull Singapore Partner to Bring Powerful Technology to the Broker’s New Futures Trading Offering

Related Posts

Tracking free-range chickens for healthier eggs

Tracking free-range chickens for healthier eggs

March 9, 2023

Will 2025 see less AI hype and more practical AI adoption/governance?

Will 2025 see less AI hype and more practical AI adoption/governance?

November 18, 2024

Tackling heightened fraud with strategic cybersecurity partnerships

Tackling heightened fraud with strategic cybersecurity partnerships

July 8, 2020

Can Japan’s GENIAC project eradicate GenAI hallucinations with knowledge graphs?

Can Japan’s GENIAC project eradicate GenAI hallucinations with knowledge graphs?

May 20, 2024

Leave a reply Cancel reply

You must be logged in to post a comment.

Awards Nomination Banner

gamification list

PARTICIPATE NOW

top placement

Whitepapers

  • Achieve Modernization Without the Complexity

    Achieve Modernization Without the Complexity

    Transforming IT infrastructure is crucial …Download Whitepaper
  • 5 Steps to Boost IT Infrastructure Reliability

    5 Steps to Boost IT Infrastructure Reliability

    In today's fast-evolving tech landscape, …Download Whitepaper
  • Simplify Payroll Setup for Your Small Business

    Simplify Payroll Setup for Your Small Business

    In our free guide, "How …Download Whitepaper
  • Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Download Whitepaper

Middle Placement

Case Studies

  • Nokia integrates all-flash data infrastructure into telco cloud for network modernization

    Nokia integrates all-flash data infrastructure into telco cloud for network modernization

    Its December 2025 upgrade supports …Read More
  • Overcoming workforce challenges in Japan’s healthcare sector with generative AI: JCHO Osaka Hospital

    Overcoming workforce challenges in Japan’s healthcare sector with generative AI: JCHO Osaka Hospital

    A digitalization initiative launching by …Read More
  • Kingspan Insulation unifies 90‑site corporate network for enhanced agility and control

    Kingspan Insulation unifies 90‑site corporate network for enhanced agility and control

    Kingspan Insulation, Expereo, global network, …Read More
  • Genspark adopts AI-driven voice automation platform to boost global communication for customers

    Genspark adopts AI-driven voice automation platform to boost global communication for customers

    Genspark, Twilio, AI voice automation, …Read More

Bottom Sidebar

Other News

  • CGTN AMERICA & CCTV UN: China in Springtime: China’s Development Opportunities for the World

    March 13, 2026
    WASHINGTON, March 13, 2026 /PRNewswire/ …Read More »
  • VIVOTEK Accelerates AI Innovation Through Network Optix Platform Integration

    March 12, 2026
    TAIPEI, March 12, 2026 /PRNewswire/ …Read More »
  • CLPS Incorporation Announces AI-Driven COBOL-to-Java Migration Solution to Accelerate Core Banking Modernization

    March 12, 2026
    HONG KONG, March 12, 2026 …Read More »
  • Wincube Launches Giftronaut (formerly Toasty Card) to Simplify How Companies Reward People Worldwide

    March 12, 2026
    SEOUL, South Korea, March 12, …Read More »
  • LightInTheBox to Report Fourth Quarter and Full Year 2025 Financial Results on Tuesday, March 24, 2026

    March 12, 2026
    SINGAPORE, March 12, 2026 /PRNewswire/ …Read More »
  • Our Brands
  • CybersecAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 DigiconAsia All Rights Reserved.