16 Total advisories
16 Vulnerabilities
0 Malware

Dependency scanning

Check whether lmdeploy is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 7.5
PyPI

GHSA-39wr-7q6h-cf68

LMDeploy has an SSRF bypass

HIGH 8.8
PyPI

CVE-2026-33625

LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading

CRITICAL 9.8
PyPI

CVE-2025-66455

LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py

CRITICAL 9.8
PyPI

CVE-2025-59953

LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy

HIGH 7.8
PyPI

CVE-2026-46517

lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out

HIGH 7.8
PyPI

CVE-2026-46432

LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization

HIGH 7.5
PyPI

CVE-2026-33626

LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading

HIGH 7.8
PyPI

CVE-2026-46432

LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization

HIGH 7.8
PyPI

CVE-2026-46517

lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out

HIGH 7.5
PyPI

CVE-2026-33626

LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading

MEDIUM 5.3
PyPI

CVE-2025-3162

LMDeploy Improper Input Validation Vulnerability

HIGH 8.8
PyPI

CVE-2025-67729

lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

MEDIUM 5.3
PyPI

CVE-2025-3163

InternLM LMDeploy code injection vulnerability

MEDIUM 5.3
PyPI

CVE-2025-3163

InternLM LMDeploy code injection vulnerability

HIGH 8.8
PyPI

CVE-2025-67729

lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

MEDIUM 5.3
PyPI

CVE-2025-3162

LMDeploy Improper Input Validation Vulnerability

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes