FixVibe

critical

vLLM Remote Code Execution via Pickle Deserialization in AsyncEngineRPCServer

A critical vulnerability (CVE-2024-9053) in vLLM allows attackers to execute arbitrary code on the host machine. The issue stems from the use of Python's pickle module to deserialize data received through the AsyncEngineRPCServer entrypoints, which lacks sufficient validation of incoming payloads.

CVE-2024-9053GHSA-cj47-qj6g-x7r4CWE-502CWE-78

Attacker Impact

An attacker can achieve full Remote Code Execution (RCE) on the server running vLLM [S2]. By sending a specially crafted malicious payload to the RPC server entrypoints, an adversary can execute arbitrary system commands with the privileges of the vLLM process [S3]. This could lead to complete system compromise, data exfiltration, or unauthorized access to AI models and sensitive training data [S2].

Root Cause

The vulnerability is rooted in the use of insecure deserialization via the Python pickle module within the AsyncEngineRPCServer component of vLLM [S2]. Python's pickle is known to be inherently unsafe when used on untrusted data, as it can be manipulated to execute arbitrary code during the unpickling process [S3]. In vLLM versions up to 0.6.0, the RPC server entrypoints do not adequately validate or sanitize the data before passing it to the pickle deserializer [S2].

Remediation

GitHub Advisory and GitLab Advisory currently list no patched version for this advisory. Move affected vLLM deployments off releases through 0.6.0 only after validating a vendor-supported non-affected release or documented downstream backport, rebuild inference images and lockfiles, and keep vLLM RPC or control-plane access limited to trusted private networks and authenticated operators [S2][S3].

Covered by FixVibe

FixVibe's GitHub repo scans flag Python dependency files that resolve vllm versions in the CVE-2024-9053 / GHSA-cj47-qj6g-x7r4 affected range, so you can upgrade.