vllm-Project vllm Remote Code Execution Vulnerability via MessageQueue.dequeue() API

Vulnerability

A remote code execution vulnerability exists in vllm-project vllm version v0.6.2. The issue arises in the MessageQueue.dequeue() API function, which improperly uses pickle.loads to deserialize data from received sockets. This flaw allows an attacker to send a malicious payload to the MessageQueue, potentially leading to the execution of arbitrary code on the victim's machine.

Impact

Exploitation of this vulnerability allows for remote code execution on the affected system.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
7.8
remediation
0.0
relevance
0.0
threat
0.1
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.