Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-29783

Опубликовано: 19 мар. 2025
Источник: nvd
CVSS3: 9
EPSS Низкий

Описание

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. When vLLM is configured to use Mooncake, unsafe deserialization exposed directly over ZMQ/TCP on all network interfaces will allow attackers to execute remote code on distributed hosts. This is a remote code execution vulnerability impacting any deployments using Mooncake to distribute KV across distributed hosts. This vulnerability is fixed in 0.8.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*
Версия от 0.6.5 (включая) до 0.8.0 (исключая)

EPSS

Процентиль: 77%
0.01105
Низкий

9 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 10
redhat
6 месяцев назад

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. When vLLM is configured to use Mooncake, unsafe deserialization exposed directly over ZMQ/TCP on all network interfaces will allow attackers to execute remote code on distributed hosts. This is a remote code execution vulnerability impacting any deployments using Mooncake to distribute KV across distributed hosts. This vulnerability is fixed in 0.8.0.

CVSS3: 9
debian
6 месяцев назад

vLLM is a high-throughput and memory-efficient inference and serving e ...

CVSS3: 9
github
6 месяцев назад

vLLM Allows Remote Code Execution via Mooncake Integration

EPSS

Процентиль: 77%
0.01105
Низкий

9 Critical

CVSS3

Дефекты

CWE-502