LMDeployGHSA-7vc5-mjwp-c8fq
LMDeploy Improper Input Validation Vulnerability
Medium5.3CVE-2025-3162 · Published Apr 3, 2025 · updated Jul 7, 2026
A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file lmdeploy/lmdeploy/vl/model/utils.py of the component PT File Handler. The manipulation leads to deserialization. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| lmdeploy PyPI | <= 0.7.1 | No fix yet |
Details and references
More LMDeploy advisories
All LMDeploy| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 16 | LMDeploy: remote code execution | Critical9.8 | 0.10.2 |
| May 21 | lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out | High7.8 | 0.13.0 |
| May 21 | LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization | High7.8 | 0.13.0 |
| Apr 21 | LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading | High7.5 | No fix yet |
| Dec 262025 | lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load() | High8.8 | 0.11.1 |
| Apr 32025 | InternLM LMDeploy code injection vulnerability | Medium5.3 | No fix yet |