Internlm

Lmdeploy

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 18.09.2026 17:13:37
  • Zuletzt bearbeitet 24.09.2026 21:25:27

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contain a code injection vulnerability in `lmdeploy/pytorch/config.py` line 620 that allows an attacker to execute arbitrary Python cod...

  • EPSS 0.7%
  • Veröffentlicht 18.09.2026 17:03:37
  • Zuletzt bearbeitet 23.09.2026 18:12:04

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize messages recei...

  • EPSS 0.37%
  • Veröffentlicht 17.09.2026 14:22:08
  • Zuletzt bearbeitet 22.09.2026 20:53:07

InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user-facing session IDs instead of internal scheduler keys. Unauthenticated attackers can send completion requ...

  • EPSS 0.49%
  • Veröffentlicht 17.09.2026 13:43:15
  • Zuletzt bearbeitet 22.09.2026 20:53:07

InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers can submit a migration_request with an empty remot...

  • EPSS 0.68%
  • Veröffentlicht 16.09.2026 15:36:02
  • Zuletzt bearbeitet 24.09.2026 21:25:27

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC communications. In...

  • EPSS 0.98%
  • Veröffentlicht 19.08.2026 21:41:28
  • Zuletzt bearbeitet 24.09.2026 20:06:30

LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes with p...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 21.07.2026 20:36:58
  • Zuletzt bearbeitet 17.09.2026 18:16:57

LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original URL without re...

  • EPSS 0.15%
  • Veröffentlicht 09.06.2026 23:05:43
  • Zuletzt bearbeitet 31.08.2026 15:17:17

LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardcoded "trust_remote_code=True" enables HF supply-chain RCE without user opt-in. Version 0.13.0 patches the issue.

  • EPSS 0.14%
  • Veröffentlicht 09.06.2026 23:05:38
  • Zuletzt bearbeitet 23.07.2026 09:10:00

LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDeploy is vulnerable to arbitrary code execution through hardcoded "trust_remote_code=True" in multiple HuggingFace model-loading cal...

Medienbericht Exploit
  • EPSS 45.25%
  • Veröffentlicht 20.04.2026 20:29:19
  • Zuletzt bearbeitet 23.04.2026 13:39:54

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Server-Side Request Forgery (SSRF) vulnerability in LMDeploy's vision-language module. The `load_image()` function in `lmdeploy/vl/ut...