vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. When vLLM is configured to use Mooncake, unsafe deserialization exposed directly over ZMQ/TCP on all network interfaces will allow attackers to execute remote code on distributed hosts. This is a remote code execution vulnerability impacting any deployments using Mooncake to distribute KV across distributed hosts. This vulnerability is fixed in 0.8.0.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-6725 vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. When vLLM is configured to use Mooncake, unsafe deserialization exposed directly over ZMQ/TCP on all network interfaces will allow attackers to execute remote code on distributed hosts. This is a remote code execution vulnerability impacting any deployments using Mooncake to distribute KV across distributed hosts. This vulnerability is fixed in 0.8.0.
Github GHSA Github GHSA GHSA-x3m8-f7g5-qhm7 vLLM Allows Remote Code Execution via Mooncake Integration
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 02 Jul 2025 06:15:00 +0900

Type Values Removed Values Added
First Time appeared Vllm
Vllm vllm
CPEs cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*
Vendors & Products Vllm
Vllm vllm

Sat, 22 Mar 2025 09:45:00 +0900

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Thu, 20 Mar 2025 23:00:00 +0900

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Critical


Thu, 20 Mar 2025 04:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 00:45:00 +0900

Type Values Removed Values Added
Description vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. When vLLM is configured to use Mooncake, unsafe deserialization exposed directly over ZMQ/TCP on all network interfaces will allow attackers to execute remote code on distributed hosts. This is a remote code execution vulnerability impacting any deployments using Mooncake to distribute KV across distributed hosts. This vulnerability is fixed in 0.8.0.
Title vLLM Allows Remote Code Execution via Mooncake Integration
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-03-22T00:02:54.404Z

Reserved: 2025-03-11T14:23:00.475Z

Link: CVE-2025-29783

cve-icon Vulnrichment

Updated: 2025-03-19T18:30:33.740Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-19T16:15:32.477

Modified: 2025-07-01T20:52:17.273

Link: CVE-2025-29783

cve-icon Redhat

Severity : Critical

Publid Date: 2025-03-19T15:33:28Z

Links: CVE-2025-29783 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses