ADVERTISEMENT
OmarosaOmarosa
No Result
View All Result
  • USA
  • Agriculture
  • Education
  • Finance
  • Billionaires
  • AI
  • Careers
  • Economy
  • Biography
  • Lists
  • USA
  • Agriculture
  • Education
  • Finance
  • Billionaires
  • AI
  • Careers
  • Economy
  • Biography
  • Lists
No Result
View All Result
OmarosaOmarosa
No Result
View All Result
Home Cybersecurity

Copy-Paste Vulnerability Exposes AI Frameworks to Systemic Security Risks

Nyongesa Sande by Nyongesa Sande
November 16, 2025
in Cybersecurity
Reading Time: 3 mins read
A A
Copy-Paste Vulnerability Exposes AI Frameworks to Systemic Security Risks
Share on FacebookShare on Twitter

Cybersecurity researchers have identified a chain of serious remote code execution vulnerabilities affecting multiple high-profile AI inference frameworks from Meta, Nvidia, Microsoft, and major open-source projects. The findings reveal that insecure code patterns were copied across repositories, creating a systemic threat across the broader AI ecosystem.

ADVERTISEMENT

A Vulnerability Spreading Through Code Reuse

According to security firm Oligo, the weaknesses share a common root. Developers reused code containing unsafe ZeroMQ and Python pickle operations, inadvertently replicating the same exploitable flaw across several frameworks. The issue first appeared in Meta’s Llama Stack before spreading into Nvidia TensorRT-LLM, vLLM, SGLang, and the Modular Max Server.

The vulnerable pattern relied on ZeroMQ’s recv_pyobj() function to receive objects before immediately passing the input into Python’s pickle.loads(). Since pickle can execute arbitrary code during deserialization, any unauthenticated ZeroMQ socket exposed to the network effectively became a remote execution vector.

How the Security Issue Propagated Across the AI Ecosystem

Oligo researchers noted numerous instances where files were copied nearly line-for-line between different projects. Some even carried comments such as “Adapted from vLLM,” indicating that the insecure design was transferred without deeper security review.

Oligo refers to this widespread vulnerability pattern as “ShadowMQ,” highlighting how flaws in communication modules silently replicate across repositories. Because AI frameworks increasingly serve as foundational layers for enterprise deployments, contaminated code can have far-reaching consequences.

ADVERTISEMENT

Patches Issued Across Major Frameworks

The flaw was initially reported to Meta in September 2024 and assigned CVE-2024-50050. Meta responded by replacing unsafe pickle-based operations with safer JSON serialization methods. This triggered a broader audit across the industry, uncovering similar vulnerabilities in:

• vLLM (CVE-2025-30165)
• Nvidia TensorRT-LLM (CVE-2025-23254)
• Modular Max Server (CVE-2025-60455)

Updated versions have since been released, and vendors have encouraged developers to upgrade immediately. Many organizations were found running inference servers with open ZeroMQ endpoints exposed on the public internet, increasing the likelihood of exploitation.

Why the Vulnerability Poses a Major Threat to AI Infrastructure

The affected inference servers process model weights, confidential user prompts, and sensitive workloads. If exploited, attackers could execute arbitrary code on GPU clusters, elevate privileges, exfiltrate proprietary models, implant persistent malware, or deploy GPU miners. The attack path could compromise both cloud and on-premise deployments.

ADVERTISEMENT

The risk is heightened by the widespread use of frameworks such as SGLang, which has been adopted by leading players including xAI, AMD, Intel, Nvidia, Oracle Cloud, LinkedIn, and Google Cloud.

Warnings and Recommendations from Security Experts

Oligo emphasized that the vulnerability reflects deeper structural challenges in the AI software supply chain. Rapid development cycles, dependency reuse, and a rush to build high-performance inference servers have left critical gaps in security assurance.

Developers are urged to upgrade to patched releases, including Meta Llama Stack v0.0.41 or later, Nvidia TensorRT-LLM 0.18.2, vLLM v0.8.0, and Modular Max Server v25.6. Additional best practices include restricting pickle usage, enforcing HMAC and TLS authentication in ZeroMQ channels, and training development teams to identify unsafe serialization patterns.

A Wake-Up Call for AI Security

The ShadowMQ incident underscores how quickly security flaws can propagate through the AI landscape when widely copied design patterns go unreviewed. As enterprise AI adoption accelerates, the industry faces a growing need for rigorous security standards to prevent small mistakes from turning into ecosystem-wide vulnerabilities.

Tags: AI securitycybersecurityinference serversMeta Llama StackMicrosoft AINvidia TensorRT-LLMpickle vulnerabilitySGLangvLLMZeroMQ flaw
ADVERTISEMENT
Previous Post

Nvidia Ignited the AI Boom — Now Its Upcoming Earnings Could Decide Its Future

Next Post

Cybersecurity in the Age of Quantum Computing

Related Posts

White Power Worldwide Cyberattack Disrupts Kenya Ministries
Cybersecurity

White Power Worldwide Cyberattack Disrupts Kenya Ministries

by Nyongesa Sande
7 months ago
0

The White power worldwide cyberattack caused widespread disruption across major Kenyan government websites on Monday morning. The coordinated breach targeted...

Read moreDetails
Load More
Next Post
Cybersecurity in the Age of Quantum Computing

Cybersecurity in the Age of Quantum Computing

ADVERTISEMENT
  • About
  • Privacy
  • Terms
  • We Are Hiring
  • DMCA
  • Contact Us
  • Advertise with us

© 2026 Omarosa Inc USA

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • 001 FM
  • 560 Power Country
  • 560 Smooth Jazz
  • About
  • Adventist Angels Watchman 90.0 FM
  • Advertise with us
  • Athiani FM 99.2 FM
  • Bahari FM 90.4 FM
  • Baraka FM 95.5 FM
  • Base Radio
  • Bethel Radio
  • Biblia Husema 96.7 FM
  • Blackpen Radio
  • Blitz FM 254
  • Bloom Radio
  • Blue Radio
  • Cambridge Radio
  • Campus Radio Kenya
  • Capital FM 98.4
  • CGTN Radio 91.9 FM
  • Chamgei FM 90.4 FM
  • Choice Radio
  • Classic 105
  • CoELIB Radio
  • Cong’asis FM 107.7 FM
  • Contact Us
  • CountryPride FM
  • Dapstrem Radio
  • DMCA Compliance Notice
  • Doctors Explain FM
  • East Africa Radio 94.7 FM
  • East FM 106.3 FM
  • Egesa FM 103.2 FM
  • Emoo FM 104.2 FM
  • Ereto FM
  • Family Radio 103.9 FM
  • Flamingo Radio
  • Gee Radio
  • Ghetto Radio 89.5 FM
  • Gotchscape Radio
  • Gukena FM 92.2 FM
  • Haki FM
  • Hey Radio Kenya
  • Hip-Hop Daily
  • Hits Radio Kenya
  • Homeboyz Radio
  • HoodRadio Kenya
  • Hope FM
  • Hot 96 FM 96.0 FM
  • Iced Radio
  • Iftiin FM 101.9 FM
  • Images: All Passports in The World
  • Inooro FM 98.9 FM
  • Islando Radio Ke
  • Jesus is Lord Radio 105.3 FM
  • Kalya FM 106.5 FM
  • Kameme FM
  • Kass FM 89.1 FM
  • KBC Coro FM
  • KBC English Service 95.6 FM
  • KBC Mayienga FM 93.5
  • KBC Pwani FM 103.1 FM
  • KBC Radio Taifa 92.9 FM
  • Kigooco FM 98.6 FM
  • Kiss 100 100.3 FM
  • Kwitu FM
  • LionafriQ Radio
  • LIVECITY RADIO Ke
  • Lulu FM 91.0 FM
  • Makinika Radio
  • Masihi Redio Afrika
  • Mayian FM
  • MBA Radio
  • Mbaitu FM 92.5 FM
  • Meru Radio 88.3 FM
  • Milele FM 104.8 FM
  • Mo Radio 88.2 FM
  • Mt Zion Radio KE
  • Mugambo Wa Mugikuyu FM
  • Mulembe FM 97.9 FM
  • Musyi FM 102.2 FM
  • Muuga FM 94.2 FM
  • Mwaki FM
  • Mwangaza Wa Neno Fm
  • Mwangaza Wa Neno FM 89.3 FM
  • Mwatu FM 93.1
  • Nation FM 96.3 FM
  • North Rift Radio
  • NRG Radio 97.1 FM
  • Omoka Radio
  • Online Radio from Kenya – Listen to Kenyan Radio Stations Free
  • Pearl Radio Ke 96.9 FM
  • PlanetFive
  • Portfolio Diversification Tools Guide
  • Power Kenya FM
  • Praise Radio Kenya
  • Privacy Policy for OmarosaOmarosa.com
  • Radio 254
  • Radio 316
  • Radio 47
  • Radio Citizen
  • Radio Daima
  • Radio Halisi
  • Radio Jambo
  • Radio Kaya 93.1 FM
  • Radio Maisha 102.7 FM
  • Radio Maria 107.3 FM
  • Radio Midnimo 90.2 FM
  • Radio Ngamia
  • Radio Ngoma 90.7 FM
  • Radio Rahma 91.5 FM
  • Radio Safari 87.9 FM
  • Radio Safina 90.7 FM
  • Radio Salaam FM 90.7 FM
  • Radio Shahidi 91.7 FM
  • Radio Simba 91.3 FM
  • Radio Waumini 88.3 FM
  • Radio44 Kenya
  • Rafiki-Farm Main Altar
  • Ramogi FM 107.1 FM
  • Relax 103 FM
  • Riri Radio 93.7 FM
  • Sauti ya Pwani FM 94.2 FM
  • Skilled Migration Resource Library: Guides, Tools & Visa Pathways
  • Smash Jam Radio
  • Smooth FM 105.5 FM
  • SoftRadio Station
  • Sound Asia FM 88.0 FM
  • Spice FM 94.4 FM
  • Spring of Worship
  • Star FM 105.9 FM
  • Terms of Use for OmarosaOmarosa.com
  • Tonzi Radio
  • Trace FM 95.3 FM
  • Truth FM 90.7 FM
  • Uiguithanio FM
  • Upward Radio
  • Utheri Radio
  • Varch Radio
  • Vuuka FM 100.4 FM
  • We Are Hiring
  • Your Hub for Insights, Inspiration, and Everything in Between

© 2026 Omarosa Inc USA