Remote Code Execution Vulnerability in LMDeploy by InternLM
CVE-2026-46517
7.8HIGH
What is CVE-2026-46517?
LMDeploy, a toolkit for managing large language models, contains a significant vulnerability due to hardcoded settings allowing for remote code execution via the Hugging Face supply chain without user consent. This issue affects versions up to and including 0.12.3 and poses a severe threat as it may allow malicious actors to execute arbitrary code on systems utilizing the affected toolkit. Currently, no public patches are available, highlighting the urgency for users to assess their risk and take appropriate security measures.
Affected Version(s)
lmdeploy <= 0.12.3
