16 Total advisories
16 Vulnerabilities
0 Malware
Dependency scanning
Check whether lmdeploy is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
GHSA-39wr-7q6h-cf68
LMDeploy has an SSRF bypass
HIGH 8.8
CVE-2026-33625
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
CRITICAL 9.8
CVE-2025-66455
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
CRITICAL 9.8
CVE-2025-59953
LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
HIGH 7.8
CVE-2026-46517
lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
HIGH 7.8
CVE-2026-46432
LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
HIGH 7.5
CVE-2026-33626
LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
HIGH 7.8
CVE-2026-46432
LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
HIGH 7.8
CVE-2026-46517
lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
HIGH 7.5
CVE-2026-33626
LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
MEDIUM 5.3
CVE-2025-3162
LMDeploy Improper Input Validation Vulnerability
HIGH 8.8
CVE-2025-67729
lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()
MEDIUM 5.3
CVE-2025-3163
InternLM LMDeploy code injection vulnerability
MEDIUM 5.3
CVE-2025-3163
InternLM LMDeploy code injection vulnerability
HIGH 8.8
CVE-2025-67729
lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()
MEDIUM 5.3
CVE-2025-3162
LMDeploy Improper Input Validation Vulnerability
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes