Meta, Nvidia and Microsoft AI frameworks share remote-code flaws
Researchers at Oligo Security found remote-code-execution vulnerabilities across AI inference frameworks from Meta, Nvidia and Microsoft, as well as open-source projects including vLLM and SGLang. The Hacker News reports that the flaws stem from unsafe Python pickle deserialisation over unauthenticated ZeroMQ connections, a code pattern copied between projects—putting organisations running these systems at risk of server or cluster compromise.
Bottom line — Oligo found the same unsafe code pattern across several frameworks; some affected projects remain unpatched or have incomplete fixes.
Go deeper 5
-
The Hacker News reports that Meta patched the original Llama framework flaw last October; the issue was also addressed in the pyzmq Python library.
-
According to The Hacker News, Nvidia fixed its TensorRT-LLM flaw in version 0.18.2, while vLLM addressed its issue by switching to the V1 engine by default.
-
The Hacker News says Modular Max Server has been fixed, while Sarathi-Serve remains unpatched and SGLang’s fixes are incomplete.
-
Oligo researcher Avi Lumelsky told The Hacker News that code reuse carried nearly identical unsafe patterns into projects maintained by different teams.
-
The Hacker News reports that a compromised inference node could enable attackers to run code on a cluster, escalate privileges or steal models.