Remote Code Execution Vulnerability in vllm Product by vllm-project
CVE-2024-11041
9.8CRITICAL
What is CVE-2024-11041?
The vllm product version 0.6.2 from vllm-project contains a vulnerability in the MessageQueue.dequeue() API function. This flaw arises from the improper handling of data received through sockets, particularly in the use of pickle.loads. An attacker can exploit this vulnerability by sending crafted input to the MessageQueue, potentially executing arbitrary code on the victim's machine. This presents a serious security risk for users operating this affected version.
Affected Version(s)
vllm-project/vllm <= unspecified