lmdeploy has 7 CVEs on record between 2025 and 2026. 1 was published in the last 90 days. The median CVSS is 7.5 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 1 prev 3
Worst active — by depth score
CVE-2026-33626High· 7.5LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading62CVE-2025-67729High· 8.8lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()49CVE-2026-46517High· 7.8lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out43CVE-2026-46432High· 7.8LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization43GHSA-39wr-7q6h-cf68High· 7.5LMDeploy has an SSRF bypass41
lmdeploy vulnerabilities
CVEs affecting lmdeploy, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
GHSA-39wr-7q6h-cf68High· 7.5LMDeploy has an SSRF bypass
LMDeploy has an SSRF bypass
CVE-2026-46432High· 7.8LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
CVE-2026-46517High· 7.8lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
CVE-2026-33626High· 7.5PoCLMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
CVE-2025-67729High· 8.8lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()
lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()
CVE-2025-3163Medium· 5.3InternLM LMDeploy code injection vulnerability
InternLM LMDeploy code injection vulnerability
CVE-2025-3162Medium· 5.3LMDeploy Improper Input Validation Vulnerability
LMDeploy Improper Input Validation Vulnerability