PT-2025-11697 · Mooncake+1 · Mooncake+1

Josephtlucas

·

Published

2025-03-19

·

Updated

2025-03-25

·

CVE-2025-29783

CVSS v3.1

9.0

Critical

VectorAV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vLLM versions prior to 0.8.0
Description The issue is a remote code execution vulnerability that occurs when vLLM is configured to use Mooncake. This vulnerability allows attackers to execute remote code on distributed hosts due to unsafe deserialization exposed directly over ZMQ/TCP on all network interfaces. The vulnerability impacts any deployments using Mooncake to distribute KV across distributed hosts.
Recommendations To resolve the issue, upgrade to version 0.8.0 or later. As a temporary workaround, consider restricting access to the vulnerable Mooncake integration until a patch is available. Avoid using the pickle.loads() function with untrusted input, and ensure that only trusted sources can send data to the affected service.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-29783
GHSA-X3M8-F7G5-QHM7
PYSEC-2025-63

Affected Products

Mooncake
Vllm