Skip to content
vLLMGHSA-cj47-qj6g-x7r4

vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints

Critical9.8CVE-2024-9053 · Published Mar 20, 2025 · updated Aug 7, 2026

vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core functionality run_server_loop() calls the function _make_handler_coro(), which directly uses cloudpickle.loads() on received messages without any sanitization. This can result in remote code execution by deserializing malicious pickle data.

GitHub advisory

Affected versions

PackageAffectedFixed in
vllm
PyPI
<= 0.6.0No fix yet
Details and references
CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-502, CWE-78
Also known as
CVE-2024-9053, PYSEC-2025-222

More vLLM advisories

All vLLM
Advisory
vLLM: code execution
Critical9.8Apr 23, 2025
vLLM vulnerable to Denial of Service by abusing xgrammar cache
Medium6.5Apr 15, 2025
vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object
Critical9.8Mar 20, 2025
vLLM Deserialization of Untrusted Data vulnerability
Critical9.8Mar 20, 2025
vLLM Allows Remote Code Execution via Mooncake Integration
Critical9.0Mar 19, 2025
vLLM denial of service via outlines unbounded cache on disk
Medium6.5Mar 19, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.