CVE-2025-29783: vLLM Allows Remote Code Execution via Mooncake Integration
(updated )
When vLLM is configured to use Mooncake, unsafe deserialization exposed directly over ZMQ/TCP on all network interfaces will allow attackers to execute remote code on distributed hosts.
References
Detect and mitigate CVE-2025-29783 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →