Over 30 critical "ShadowMQ" vulnerabilities, stemming from insecure ZeroMQ `recv_pyobj()` and Python `pickle` deserialization, affect leading AI inference engines such as Meta Llama LLM and NVIDIA TensorRT-LLM. These flaws enable remote code execution, data theft, and privilege escalation, with specific CVEs like CVE-2024-50050 attributed, and active exploitation has been observed.
Why This Matters
The evidence matters to defenders using Meta because it could let an attacker run code in affected environments.
Recommended Action
Confirm whether vLLM is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
CVE: CVE-2024-50050, CVE-2025-23254
Affected