A critical vulnerability in kvcache-ai ktransformers exposed the balance_serve scheduler to unauthenticated remote code execution through unsafe Python pickle deserialization on a ZeroMQ ROUTER socket. The flaw, tracked as CVE-2026-63767 and GHSA-83vp-v6wg-x93x, affects versions through 0.6.3. The vulnerable SchedulerServer bound its RPC socket to all interfaces using tcp://*, then passed incoming messages directly to pickle.loads(), allowing any reachable host to send a crafted payload with a malicious __reduce__ method and execute arbitrary shell commands as the server process.
The issue was documented in a GitHub security report that validated end-to-end code execution and noted that the scheduler port is auto-assigned, requiring discovery before exploitation. Maintainers remediated the exposure in commit def0f9313d6e063b5c5ccdfa1f6707f7a40dfdca, changing the bind address to tcp://127.0.0.1 in both affected sched_rpc.py paths so the scheduler is reachable only over localhost, which matches the intended SchedulerClient design. The vulnerability is classified as CWE-502 and carries a CVSS 3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting high risk to confidentiality, integrity, and availability.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Public advisories identified the issue as CVE-2026-63767 and GHSA-83vp-v6wg-x93x, describing unauthenticated remote code execution in ktransformers through version 0.6.3 via malicious pickle payloads sent to the SchedulerServer ZMQ socket. The advisories also noted that the flaw was fixed by commit def0f93.
A security fix was merged into kvcache-ai/ktransformers that changed the scheduler ZMQ ROUTER socket bind address from all interfaces to 127.0.0.1, removing external network exposure for the vulnerable RPC service. The merged commit was def0f9313d6e063b5c5ccdfa1f6707f7a40dfdca and applied to both affected sched_rpc.py copies.
A GitHub security advisory described an unauthenticated remote code execution flaw in the ktransformers balance_serve scheduler, caused by a ZeroMQ ROUTER socket exposed on all interfaces and unsafe pickle.loads deserialization. The report said the issue was validated end-to-end with a crafted payload executing code before normal message handling.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcecvefeed.io
Open sourcevulncheck.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.