Internlm

Lmdeploy

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.98%
  • Veröffentlicht 19.08.2026 21:41:28
  • Zuletzt bearbeitet 20.08.2026 15:18:38

LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes with p...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 21.07.2026 20:36:58
  • Zuletzt bearbeitet 05.08.2026 19:44:29

LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original URL without re...

  • EPSS 0.15%
  • Veröffentlicht 09.06.2026 23:05:43
  • Zuletzt bearbeitet 23.07.2026 09:10:00

LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardcoded "trust_remote_code=True" enables HF supply-chain RCE without user opt-in. At time of publication, there are no publicly avail...

  • EPSS 0.14%
  • Veröffentlicht 09.06.2026 23:05:38
  • Zuletzt bearbeitet 23.07.2026 09:10:00

LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDeploy is vulnerable to arbitrary code execution through hardcoded "trust_remote_code=True" in multiple HuggingFace model-loading cal...

Medienbericht Exploit
  • EPSS 45.25%
  • Veröffentlicht 20.04.2026 20:29:19
  • Zuletzt bearbeitet 23.04.2026 13:39:54

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Server-Side Request Forgery (SSRF) vulnerability in LMDeploy's vision-language module. The `load_image()` function in `lmdeploy/vl/ut...

  • EPSS 0.54%
  • Veröffentlicht 26.12.2025 21:54:10
  • Zuletzt bearbeitet 31.12.2025 21:31:22

LMDeploy is a toolkit for compressing, deploying, and serving LLMs. Prior to version 0.11.1, an insecure deserialization vulnerability exists in lmdeploy where torch.load() is called without the weights_only=True parameter when loading model checkpoi...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 03.04.2025 16:15:37
  • Zuletzt bearbeitet 23.04.2025 15:31:12

A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerability is the function Open of the file lmdeploy/docs/en/conf.py. The manipulation leads to code injection. It is possible to launch...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 03.04.2025 15:15:53
  • Zuletzt bearbeitet 23.04.2025 22:29:10

A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file lmdeploy/lmdeploy/vl/model/utils.py of the component PT File Handler. The manipulation leads to dese...