CVE-2025-66455 | InternLM LMDeploy up to 0.15.x PyTorch backend /distserve/p2p_connect recv_pyobj deserialization

SecurityVulns

A vulnerability identified as critical has been detected in InternLM LMDeploy up to 0.15.x. Affected by this issue is the function recv_pyobj of the file /distserve/p2p_connect of the component PyTorch backend. Performing a manipulation results in deserialization.

This vulnerability is identified as CVE-2025-66455. The attack can be initiated remotely. There is not any exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More