Remote Code Execution Vulnerability in LMDeploy by InternLM
CVE-2026-46517

7.8HIGH

Key Information:

Vendor

Internlm

Status
Vendor
CVE Published:
9 June 2026

What is CVE-2026-46517?

LMDeploy, a toolkit for managing large language models, contains a significant vulnerability due to hardcoded settings allowing for remote code execution via the Hugging Face supply chain without user consent. This issue affects versions up to and including 0.12.3 and poses a severe threat as it may allow malicious actors to execute arbitrary code on systems utilizing the affected toolkit. Currently, no public patches are available, highlighting the urgency for users to assess their risk and take appropriate security measures.

Affected Version(s)

lmdeploy <= 0.12.3

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.