Internlm
Internlm Lmdeploy: vulnerabilidades y CVE
Internlm Lmdeploy tiene 13 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses11
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-33625 | Alta (8.8) | 0.44% | — | 18 sept 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contain a code injection vulnerability in `lmdeploy/pytorch/config.py` line 620 that allows an attacker… |
| CVE-2025-66455 | Crítica (9.8) | 0.69% | — | 18 sept 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used… |
| CVE-2026-92983 | Alta (8.7) | 0.66% | — | 17 sept 2026 | InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user-facing session IDs instead of internal scheduler keys. Unauthenticated… |
| CVE-2026-92971 | Alta (8.7) | 0.70% | — | 17 sept 2026 | InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers can submit a… |
| CVE-2025-59953 | Crítica (9.8) | 0.80% | — | 16 sept 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for… |
| CVE-2026-76850 | Crítica (9.3) | 1.3% | — | 19 ago 2026 | LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which… |
| CVE-2026-63764 | Alta (7.7) | 0.51% | — | 21 jul 2026 | LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates… |
| CVE-2026-46517 | Alta (7.8) | 0.43% | — | 10 jun 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardcoded "trust_remote_code=True" enables HF supply-chain RCE without user opt-in. Version 0.13.0… |
| CVE-2026-46432 | Alta (7.8) | 0.20% | — | 10 jun 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDeploy is vulnerable to arbitrary code execution through hardcoded "trust_remote_code=True" in… |
| CVE-2026-33626 | Alta (7.5) | 1.5% | — | 20 abr 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Server-Side Request Forgery (SSRF) vulnerability in LMDeploy's vision-language module. The… |
| CVE-2025-67729 | Alta (8.8) | 0.60% | — | 26 dic 2025 | LMDeploy is a toolkit for compressing, deploying, and serving LLMs. Prior to version 0.11.1, an insecure deserialization vulnerability exists in lmdeploy where torch.load() is called without the weights_only=True… |
| CVE-2025-3163 | Media (4.8) | 0.37% | — | 3 abr 2025 | A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerability is the function Open of the file lmdeploy/docs/en/conf.py. The manipulation leads to code… |
| CVE-2025-3162 | Media (4.8) | 0.32% | — | 3 abr 2025 | A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file lmdeploy/lmdeploy/vl/model/utils.py of the component PT File Handler.… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.