Attacker Impact
An attacker can achieve full Remote Code Execution (RCE) on the server running vLLM [S2]. By sending a specially crafted malicious payload to the RPC server entrypoints, an adversary can execute arbitrary system commands with the privileges of the vLLM process [S3]. This could lead to complete system compromise, data exfiltration, or unauthorized access to AI models and sensitive training data [S2].
Root Cause
The vulnerability is rooted in the use of insecure deserialization via the Python pickle module within the AsyncEngineRPCServer component of vLLM [S2]. Python's pickle is known to be inherently unsafe when used on untrusted data, as it can be manipulated to execute arbitrary code during the unpickling process [S3]. In vLLM versions up to 0.6.0, the RPC server entrypoints do not adequately validate or sanitize the data before passing it to the pickle deserializer [S2].
Remediation
GitHub Advisory and GitLab Advisory currently list no patched version for this advisory. Move affected vLLM deployments off releases through 0.6.0 only after validating a vendor-supported non-affected release or documented downstream backport, rebuild inference images and lockfiles, and keep vLLM RPC or control-plane access limited to trusted private networks and authenticated operators [S2][S3].
Covered by FixVibe
FixVibe's GitHub repo scans flag Python dependency files that resolve vllm versions in the CVE-2024-9053 / GHSA-cj47-qj6g-x7r4 affected range, so you can upgrade.
