Arbitrary Code Execution in LMDeploy by InternLM
CVE-2026-46432
7.8HIGH
What is CVE-2026-46432?
LMDeploy, a toolkit designed for compressing and deploying large language models, has been found to be susceptible to arbitrary code execution vulnerabilities. This issue arises from hardcoded configurations that permit unsafe code execution through the 'trust_remote_code=True' parameter present in various HuggingFace model-loading operations. As of now, no patches are publicly available to remediate this security flaw, leaving users at significant risk when utilizing versions 0.12.3 and earlier.
Affected Version(s)
lmdeploy <= 0.12.3
