Skip to content

LMDeploy security advisories

10 advisories · 8 critical or high in 12 months · latest Sep 18

10 advisories

DateAdvisory
Sep 18LMDeploy has an SSRF bypass
GHSA-39wr-7q6h-cf68High7.5fixed in 0.15.0
Sep 18LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
CVE-2026-33625High8.8fixed in 0.12.3
Sep 18LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
CVE-2025-66455Critical9.8fixed in 0.16.0
Sep 16LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
CVE-2025-59953Critical9.8fixed in 0.10.2
May 21lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
CVE-2026-46517High7.8fixed in 0.13.0
May 21LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
CVE-2026-46432High7.8fixed in 0.13.0
Apr 21LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
CVE-2026-33626High7.5no fix yet
Dec 262025lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()
CVE-2025-67729High8.8fixed in 0.11.1
Apr 32025InternLM LMDeploy code injection vulnerability
CVE-2025-3163Medium5.3no fix yet
Apr 32025LMDeploy Improper Input Validation Vulnerability
CVE-2025-3162Medium5.3no fix yet
About LMDeploy

Compression, deployment and serving for LLMs.

Packages watched: lmdeploy (PyPI).

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.