Skip to content
LMDeployGHSA-jfvg-qm4p-473x

InternLM LMDeploy code injection vulnerability

Medium5.3CVE-2025-3163 · Published Apr 3, 2025 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
lmdeploy
PyPI
<= 0.7.1No fix yet
Details and references

A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerability is the function Open of the file lmdeploy/docs/en/conf.py. The manipulation leads to code injection. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-74, CWE-94
Also known as
CVE-2025-3163, PYSEC-2026-1579

More LMDeploy advisories

All LMDeploy
DateAdvisory
Apr 32025LMDeploy Improper Input Validation Vulnerability
CVE-2025-3162Medium5.3no fix yet
Dec 262025lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()
CVE-2025-67729High8.8fixed in 0.11.1
Apr 21LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
CVE-2026-33626High7.5no fix yet
May 21LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
CVE-2026-46432High7.8fixed in 0.13.0
May 21lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
CVE-2026-46517High7.8fixed in 0.13.0
Sep 16LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
CVE-2025-59953Critical9.8fixed in 0.10.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.