VulnSea

lmdeploy vulnerabilities

CVEs whose affected-version data names the lmdeploy package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

13 CVEsRSS

CVE-2025-66455Critical· 9.8
3d ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize m…

MidnightInternLM · lmdeployEPSS 0.70%via NVD
GHSA-39wr-7q6h-cf68High· 7.5
3d ago

LMDeploy has an SSRF bypass

LMDeploy has an SSRF bypass

Twilightlmdeploy · lmdeployvia OSV
CVE-2026-33625High· 8.8
3d ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contain a code injection vulnerability in `lmdeploy/pytorch/config.py` line 620 that allows an attacker to execute arbitra…

TwilightInternLM · lmdeployEPSS 0.24%via NVD
CVE-2026-92983High· 7.5PoC
4d ago

InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user-facing session IDs instead of internal scheduler keys

InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user-facing session IDs instead of internal scheduler keys. Unauthenticated attackers can send co…

MidnightInternLM · lmdeployEPSS 0.37%via NVD
CVE-2026-92971High· 7.5PoC
4d ago

InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine

InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers can submit a migration_request with a…

MidnightInternLM · lmdeployEPSS 0.49%via NVD
CVE-2025-59953Critical· 9.8PoC
5d ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC commu…

AbyssalInternLM · lmdeployEPSS 0.68%via NVD
CVE-2026-63764High· 8.6PoC
2mo ago

LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original U…

LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original U…

Midnightinternlm · lmdeployEPSS 0.39%via NVD
CVE-2026-46432High· 7.8
4mo ago

LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization

LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization

Twilightlmdeploy · lmdeployEPSS 0.14%via OSV
CVE-2026-46517High· 7.8
4mo ago

lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out

lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out

Twilightlmdeploy · lmdeployEPSS 0.16%via OSV
CVE-2026-33626High· 7.5PoC
5mo ago

LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading

LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading

Midnightlmdeploy · lmdeployEPSS 45%via OSV
CVE-2025-67729High· 8.8
8mo ago

lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

Twilightlmdeploy · lmdeployEPSS 0.60%via OSV
CVE-2025-3163Medium· 5.3
1y ago

InternLM LMDeploy code injection vulnerability

InternLM LMDeploy code injection vulnerability

Sunlitlmdeploy · lmdeployEPSS 0.37%via OSV
CVE-2025-3162Medium· 5.3
1y ago

LMDeploy Improper Input Validation Vulnerability

LMDeploy Improper Input Validation Vulnerability

Sunlitlmdeploy · lmdeployEPSS 0.32%via OSV
lmdeploy vulnerabilities (CVEs) · VulnSea