MEDIUM 5.3 PyPI

InternLM LMDeploy code injection vulnerability

GHSA-jfvg-qm4p-473x · CVE-2025-3163 · PYSEC-2026-1579

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerability is the function Open of the file lmdeploy/docs/en/conf.py. The manipulation leads to code injection. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

Ready to move

Start Securing

Free, no credit card | First findings in minutes