vllm-project vllm
cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*
- v0.6.2
A remote code execution vulnerability exists in vllm-project vllm version v0.6.2. The issue arises in the MessageQueue.dequeue() API function, which improperly uses pickle.loads to deserialize data from received sockets. This flaw allows an attacker to send a malicious payload to the MessageQueue, potentially leading to the execution of arbitrary code on the victim's machine.
Exploitation of this vulnerability allows for remote code execution on the affected system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.