Last seen December 7, 2025

Meta Remote Code Execution Vulnerability

Over 30 critical "ShadowMQ" vulnerabilities, stemming from insecure ZeroMQ `recv_pyobj()` and Python `pickle` deserialization, affect leading AI inference engines such as Meta Llama LLM and NVIDIA TensorRT-LLM. These flaws enable remote code execution, data theft, and privilege escalation, with specific CVEs like CVE-2024-50050 attributed, and active exploitation has been observed.

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

Over 30 critical "ShadowMQ" vulnerabilities, stemming from insecure ZeroMQ `recv_pyobj()` and Python `pickle` deserialization, affect leading AI inference engines such as Meta Llama LLM and NVIDIA TensorRT-LLM. These flaws enable remote code execution, data theft, and privilege escalation, with specific CVEs like CVE-2024-50050 attributed, and active exploitation has been observed.

Why This Matters

The evidence matters to defenders using Meta because it could let an attacker run code in affected environments.

Recommended Action

Confirm whether vLLM is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Dec 07, 2025 05:30

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

Amazon AWSMetaMicrosoftNvidiaAI inference frameworksMeta Llama Stack

Authoritative Intelligence

CVE CVE-2024-50050, CVE-2025-23254 Incident identifier

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Public GitHub References

Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ€” it does not fetch or display exploit code.

No public GitHub repositories were found for CVE-2025-23254.

Timeline

  • Incident first seen
    Nov 14, 2025 05:30

    BugSkan first recorded this incident.

  • Copy-paste vulnerability hits AI inference frameworks at Meta, Nvidia, and Microsoft - csoonline.com
    Nov 14, 2025 05:30

    csoonline.com ยท Vulnerability

  • Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference Frameworks - The Hacker News
    Nov 14, 2025 05:30

    thehackernews.com ยท Vulnerability

  • ShadowMQ Vulnerabilities: Over 30 Critical Flaws in Meta Llama, NVIDIA TensorRT-LLM, vLLM, and Other AI Inference Engines Enable Data Theft and Remote Code Execution - Rescana
    Dec 07, 2025 05:30

    rescana.com ยท Vulnerability

  • Latest observed development
    Dec 07, 2025 05:30

    Most recent source or update associated with this incident.

Sources

Copy-paste vulnerability hits AI inference frameworks at Meta, Nvidia, and Microsoft - csoonline.com

csoonline.com ยท Nov 14, 2025 05:30

A series of critical Remote Code Execution (RCE) vulnerabilities, dubbed 'ShadowMQ,' were discovered in major AI inference frameworks (Meta Llama Stack, Nvidia TensorRT-LLM, vLLM, etc.) due to insecure Python pickle deserialization over unauthenticated ZeroMQ sockets. These flaws, including CVE-2024-50050 and CVE-2025-23254, were widely replicated through code reuse, creating systemic risk for arbitrary code execution on enterprise AI infrastructure and potential data exfiltration.

Open publisher source
Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference Frameworks - The Hacker News

thehackernews.com ยท Nov 14, 2025 05:30

Critical remote code execution vulnerabilities have been discovered across major AI inference engines, including Meta, Nvidia, and Microsoft, stemming from the unsafe use of ZeroMQ and Python's pickle deserialization. This "ShadowMQ" pattern allows attackers to execute arbitrary code, escalate privileges, and conduct model theft by exploiting unauthenticated ZMQ TCP sockets.

Open publisher source
ShadowMQ Vulnerabilities: Over 30 Critical Flaws in Meta Llama, NVIDIA TensorRT-LLM, vLLM, and Other AI Inference Engines Enable Data Theft and Remote Code Execution - Rescana

rescana.com ยท Dec 07, 2025 05:30

Over 30 critical "ShadowMQ" vulnerabilities, stemming from insecure ZeroMQ `recv_pyobj()` and Python `pickle` deserialization, affect leading AI inference engines such as Meta Llama LLM and NVIDIA TensorRT-LLM. These flaws enable remote code execution, data theft, and privilege escalation, with specific CVEs like CVE-2024-50050 attributed, and active exploitation has been observed.

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

โ† Back to incident intelligence