Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-76850

LMDeploy Remote Code Execution via Unsafe Pickle Deserialization in the Disaggregated Serving Peer Connector
Back to all
CVE

CVE-2026-76850

LMDeploy Remote Code Execution via Unsafe Pickle Deserialization in the Disaggregated Serving Peer Connector

LMDeploy deserializes disaggregated-serving peer messages with pickle. The handlezmqrecv coroutine in lmdeploy/pytorch/disagg/conn/engineconn.py reads peer-to-peer cache-free requests with recvpyobj(), which deserializes the received bytes with pickle.loads(), and the isinstance check against DistServeCacheFreeRequest runs only after deserialization has already completed. The peer that supplies those bytes is caller-controlled: p2pconnect passes remoteengineendpointinfo.zmqaddress from the request body to connect() on the ZMQ PULL socket, and the POST /distserve/p2pinitialize and /distserve/p2pconnect endpoints in lmdeploy/serve/openai/apiserver.py apply no authentication unless the server is started with api_keys, which defaults to None. A remote attacker can direct an engine to pull from a ZMQ endpoint under their control and execute arbitrary code in the engine process. Deployments that do not enable disaggregated serving are not affected, because the receive loop is only started once the migration backend accepts the connection.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.3
-
4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
C
H
U
0
-
C
H
U
9.3
-
4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Related Resources

No items found.

References

https://pypi.org, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76850.json, https://github.com/InternLM/lmdeploy/releases/tag/v0.16.0, https://nvd.nist.gov/vuln/detail/CVE-2026-76850, https://www.vulncheck.com/advisories/lmdeploy-remote-code-execution-via-unsafe-pickle-deserialization-in-the-disaggregated-serving-peer-connector, https://github.com/InternLM/lmdeploy/issues/4804, https://github.com/InternLM/lmdeploy/commit/f05b4ad8bf2e2d84101a1d63b3c44fadd99223b2, https://github.com/InternLM/lmdeploy, https://github.com/InternLM/lmdeploy/blob/v0.15.0/lmdeploy/pytorch/disagg/conn/engineconn.py#L61, https://github.com/InternLM/lmdeploy/blob/v0.15.0/lmdeploy/pytorch/disagg/conn/engineconn.py#L79

Severity

0

CVSS Score
0
10

Basic Information

Base CVSS
0
EPSS Probability
0.01271%
EPSS Percentile
0.68678%
Introduced Version
9098ae8c1abf35fdf81fb279d466c12766973aa7,0.9.2.post1
Fix Available
1208bf006bbac69f1f012ceafeeeb70f623b632c,0.16.0

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading