OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2025-59953

CRITICAL · CVSS 9.8 EPSS 0.80% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The LMDeploy toolkit, specifically versions 0.9.1 through 0.10.1, is vulnerable due to its use of unsanitized deserialization via the pickles.loads() function in the AsyncRPCServer, allowing for remote code execution. This critical vulnerability poses significant risks to any organization utilizing affected versions, as attackers could exploit it to execute arbitrary code on the server. Users of LMDeploy should prioritize upgrading to version 0.10.2 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-59953
Severity
CRITICAL
CVSS
9.8
EPSS
0.80%

Original NVD Description

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC communications. In its core functionality call_and_response(), I found it will directly use the pickles.loads() to deserialize the received messages without any sanitization, hence resulting in a remote code execution vulnerability by this RPC server. Version 0.10.2 contains a patch.