LMDeployGHSA-jfvg-qm4p-473x
InternLM LMDeploy code injection vulnerability
Medium5.3CVE-2025-3163 · Published Apr 3, 2025 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| lmdeploy PyPI | <= 0.7.1 | No fix yet |
Details and references
A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerability is the function Open of the file lmdeploy/docs/en/conf.py. The manipulation leads to code injection. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
More LMDeploy advisories
All LMDeploy| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 32025 | LMDeploy Improper Input Validation Vulnerability CVE-2025-3162Medium5.3no fix yet | Medium5.3 | No fix yet |
| Dec 262025 | lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load() CVE-2025-67729High8.8fixed in 0.11.1 | High8.8 | 0.11.1 |
| Apr 21 | LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading CVE-2026-33626High7.5no fix yet | High7.5 | No fix yet |
| May 21 | LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization CVE-2026-46432High7.8fixed in 0.13.0 | High7.8 | 0.13.0 |
| May 21 | lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out CVE-2026-46517High7.8fixed in 0.13.0 | High7.8 | 0.13.0 |
| Sep 16 | LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy CVE-2025-59953Critical9.8fixed in 0.10.2 | Critical9.8 | 0.10.2 |