VulnSea

lmdeploy has 7 CVEs on record between 2025 and 2026. 1 was published in the last 90 days. The median CVSS is 7.5 (high). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
1 prev 3

Weakness classes

Products

  • lmdeploy 7
7
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

lmdeploy vulnerabilities

CVEs affecting lmdeploy, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

GHSA-39wr-7q6h-cf68High· 7.5
4d ago

LMDeploy has an SSRF bypass

LMDeploy has an SSRF bypass

Twilightlmdeploy · lmdeployvia OSV
CVE-2026-46432High· 7.8
4mo ago

LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization

LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization

Twilightlmdeploy · lmdeployEPSS 0.14%via OSV
CVE-2026-46517High· 7.8
4mo ago

lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out

lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out

Twilightlmdeploy · lmdeployEPSS 0.16%via OSV
CVE-2026-33626High· 7.5PoC
5mo ago

LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading

LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading

Midnightlmdeploy · lmdeployEPSS 45%via OSV
CVE-2025-67729High· 8.8
9mo ago

lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

Twilightlmdeploy · lmdeployEPSS 0.60%via OSV
CVE-2025-3163Medium· 5.3
1y ago

InternLM LMDeploy code injection vulnerability

InternLM LMDeploy code injection vulnerability

Sunlitlmdeploy · lmdeployEPSS 0.37%via OSV
CVE-2025-3162Medium· 5.3
1y ago

LMDeploy Improper Input Validation Vulnerability

LMDeploy Improper Input Validation Vulnerability

Sunlitlmdeploy · lmdeployEPSS 0.32%via OSV
lmdeploy vulnerabilities (CVEs) · VulnSea