MEDIUM 5.3 PyPI
LMDeploy Improper Input Validation Vulnerability
GHSA-7vc5-mjwp-c8fq · CVE-2025-3162 · PYSEC-2026-1577
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file lmdeploy/lmdeploy/vl/model/utils.py of the component PT File Handler. The manipulation leads to deserialization. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-3162
- WEB https://github.com/InternLM/lmdeploy/issues/3255
- WEB https://github.com/InternLM/lmdeploy/issues/3255#issue-2918985270
- PACKAGE https://github.com/InternLM/lmdeploy
- WEB https://vuldb.com/?ctiid.303108
- WEB https://vuldb.com/?id.303108
- WEB https://vuldb.com/?submit.542520
Ready to move
Start Securing
Free, no credit card | First findings in minutes