Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-9xq9-36w5-q796
  • PyPI/lmdeploy
lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out yesterday
  • No fix available
  • Severity - 7.8 (High)
GHSA-m549-qq94-fvhg
  • PyPI/lmdeploy
LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization yesterday
  • Fix available
  • Severity - 7.8 (High)
GHSA-6w67-hwm5-92mq
  • PyPI/lmdeploy
LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading 21 Apr
  • No fix available
  • Severity - 7.5 (High)
GHSA-9pf3-7rrr-x5jh
  • PyPI/lmdeploy
lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load() 26 Dec 2025
  • Fix available
  • Severity - 8.8 (High)
GHSA-jfvg-qm4p-473x
  • PyPI/lmdeploy
InternLM LMDeploy code injection vulnerability 03 Apr 2025
  • No fix available
  • Severity - 4.8 (Medium)
GHSA-7vc5-mjwp-c8fq
  • PyPI/lmdeploy
LMDeploy Improper Input Validation Vulnerability 03 Apr 2025
  • No fix available
  • Severity - 4.8 (Medium)