Meta Remote Code Execution Vulnerability
Over 30 critical "ShadowMQ" vulnerabilities, stemming from insecure ZeroMQ `recv_pyobj()` and Python `pickle` deserialization, affect leading AI inference engines such as Meta Llama LLM and NVIDIA TensorRT-LLM. These flaws enable remote code execution, data theft, and privilege escalation, with specific CVEs like CVE-2024-50050 attributed, and active exploitation has been observed.
STABLE
What Happened
Over 30 critical "ShadowMQ" vulnerabilities, stemming from insecure ZeroMQ `recv_pyobj()` and Python `pickle` deserialization, affect leading AI inference engines such as Meta Llama LLM and NVIDIA TensorRT-LLM. These flaws enable remote code execution, data theft, and privilege escalation, with specific CVEs like CVE-2024-50050 attributed, and active exploitation has been observed.
Why This Matters
The evidence matters to defenders using Meta because it could let an attacker run code in affected environments.
Recommended Action
Confirm whether vLLM is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
Exposure
Exposure unknown
Dec 07, 2025 05:30
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Primary entities:
Authoritative Intelligence
Public GitHub References
Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ it does not fetch or display exploit code.
CVE-2024-50050: 1 public repository reference found.
Public exploit-related repository
LlamaStack-RCE: Deterministic Supply Chain Exploitation & Hardening Framework [CVE-2024-50050] Focus on AI Security Research AI-SupplyChain-Poisoning: Advanced PVM Opcode Manipulation & ZeroMQ Injection Lab
0 stars
Open repositoryA public PoC or exploit-related repository means weaponization material may exist in the open. It does not prove your environment was targeted.
Timeline
-
Incident first seen
Nov 14, 2025 05:30BugSkan first recorded this incident.
-
Copy-paste vulnerability hits AI inference frameworks at Meta, Nvidia, and Microsoft - csoonline.com
Nov 14, 2025 05:30csoonline.com ยท Vulnerability
-
Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference Frameworks - The Hacker News
Nov 14, 2025 05:30thehackernews.com ยท Vulnerability
-
ShadowMQ Vulnerabilities: Over 30 Critical Flaws in Meta Llama, NVIDIA TensorRT-LLM, vLLM, and Other AI Inference Engines Enable Data Theft and Remote Code Execution - Rescana
Dec 07, 2025 05:30rescana.com ยท Vulnerability
-
Latest observed development
Dec 07, 2025 05:30Most recent source or update associated with this incident.
Sources
csoonline.com ยท Nov 14, 2025 05:30
A series of critical Remote Code Execution (RCE) vulnerabilities, dubbed 'ShadowMQ,' were discovered in major AI inference frameworks (Meta Llama Stack, Nvidia TensorRT-LLM, vLLM, etc.) due to insecure Python pickle deserialization over unauthenticated ZeroMQ sockets. These flaws, including CVE-2024-50050 and CVE-2025-23254, were widely replicated through code reuse, creating systemic risk for arbitrary code execution on enterprise AI infrastructure and potential data exfiltration.
Open publisher sourcethehackernews.com ยท Nov 14, 2025 05:30
Critical remote code execution vulnerabilities have been discovered across major AI inference engines, including Meta, Nvidia, and Microsoft, stemming from the unsafe use of ZeroMQ and Python's pickle deserialization. This "ShadowMQ" pattern allows attackers to execute arbitrary code, escalate privileges, and conduct model theft by exploiting unauthenticated ZMQ TCP sockets.
Open publisher sourcerescana.com ยท Dec 07, 2025 05:30
Over 30 critical "ShadowMQ" vulnerabilities, stemming from insecure ZeroMQ `recv_pyobj()` and Python `pickle` deserialization, affect leading AI inference engines such as Meta Llama LLM and NVIDIA TensorRT-LLM. These flaws enable remote code execution, data theft, and privilege escalation, with specific CVEs like CVE-2024-50050 attributed, and active exploitation has been observed.
Open publisher sourceRelated Incidents
Other BugSkan incidents that share identifiers, products, or vendors with this report.
My Interests Match
Create an account to see which incidents overlap with your interests.