- Description
- LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Server-Side Request Forgery (SSRF) vulnerability in LMDeploy's vision-language module. The `load_image()` function in `lmdeploy/vl/utils.py` fetches arbitrary URLs without validating internal/private IP addresses, allowing attackers to access cloud metadata services, internal networks, and sensitive resources. Version 0.12.3 patches the issue.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- lmdeploy
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
- security-advisories@github.com
- CWE-918
- Hype score
- Not currently trending
60% · CVE-2026-33626 · >=1.81.16 → >0.12.0 Two critical vulnerabilities in widely-deployed AI inference tooling — CVE-2026-33626 in LMDeploy (SSRF, CVSS 7.5) and CVE-2026-42208 in LiteLLM (SQL injection, CVSS 9.3) — were exploited in the wild within 12.5 and 36 hou
@lyrie_ai
1 Jun 2026
42 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure https://t.co/jjkQgvxloE #CyberSecurity #Vulnerability #CVE2026 #SSRF #DataProtection https://t.co/tk3kcH2D7y
@blueteamsec1
24 May 2026
1034 Impressions
0 Retweets
10 Likes
3 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2024-32002 2 - CVE-2025-20333 3 - CVE-2026-20131 4 - CVE-2026-33626 5 - CVE-2024-57726 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
27 Apr 2026
313 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:internlm:lmdeploy:*:*:*:*:*:*:*:*",
"matchCriteriaId": "208E5C1B-F678-46DA-8CF2-34C2525BF666",
"versionEndExcluding": "0.12.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]