Internlm Lmdeploy vulnerabilities
6 known vulnerabilities affecting internlm/lmdeploy.
Total CVEs
6
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH6
Vulnerabilities
Page 1 of 1
CVE-2026-33626P1HIGHCVSS 7.5ExploitedPoCfixed in 0.12.32026-04-20
CVE-2026-33626 [HIGH] CWE-918 CVE-2026-33626: LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Server-Side Request Forgery (SSRF) vulnerability in LMDeploy's vision-language module. The `load_image()` function in `lmdeploy/vl/utils.py` fetches arbitrary URLs without validating internal/private IP addresses, allowing attackers to a
ghsanvd
CVE-2025-67729P3HIGHCVSS 8.8fixed in 0.11.12025-12-26
CVE-2025-67729 [HIGH] CWE-502 CVE-2025-67729: LMDeploy is a toolkit for compressing, deploying, and serving LLMs. Prior to version 0.11.1, an inse
LMDeploy is a toolkit for compressing, deploying, and serving LLMs. Prior to version 0.11.1, an insecure deserialization vulnerability exists in lmdeploy where torch.load() is called without the weights_only=True parameter when loading model checkpoint files. This allows an attacker to execute arbitrary code on the victim's machine when they load a ma
ghsanvdosv
CVE-2025-3162P3HIGHCVSS 7.8≤ 0.7.1v0.7.0+1 more2025-04-03
CVE-2025-3162 [HIGH] CWE-20 CVE-2025-3162: A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affe
A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file lmdeploy/lmdeploy/vl/model/utils.py of the component PT File Handler. The manipulation leads to deserialization. Attacking locally is a requirement. The exploit has been disclosed to the public and may be u
ghsanvdosv
CVE-2026-46432P3HIGHCVSS 7.8≤ 0.12.32026-06-10
CVE-2026-46432 [HIGH] CWE-94 CVE-2026-46432: LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.1
LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDeploy is vulnerable to arbitrary code execution through hardcoded "trust_remote_code=True" in multiple HuggingFace model-loading call sites. At time of publication, there are no publicly available patches.
ghsanvd
CVE-2025-3163P3HIGHCVSS 7.8≤ 0.7.1v0.7.0+1 more2025-04-03
CVE-2025-3163 [HIGH] CWE-74 CVE-2025-3163: A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affect
A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerability is the function Open of the file lmdeploy/docs/en/conf.py. The manipulation leads to code injection. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
ghsanvdosv
CVE-2026-46517P3HIGHCVSS 7.8≤ 0.12.32026-06-10
CVE-2026-46517 [HIGH] CWE-94 CVE-2026-46517: LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.1
LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardcoded "trust_remote_code=True" enables HF supply-chain RCE without user opt-in. At time of publication, there are no publicly available patches.
ghsanvd