MEDIUM 5.3 PyPI

LMDeploy Improper Input Validation Vulnerability

GHSA-7vc5-mjwp-c8fq · CVE-2025-3162 · PYSEC-2026-1577

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file lmdeploy/lmdeploy/vl/model/utils.py of the component PT File Handler. The manipulation leads to deserialization. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

Ready to move

Start Securing

Free, no credit card | First findings in minutes