Server-Side Request Forgery Vulnerability in lmdeploy by InternLM
CVE-2026-63764
9.2CRITICAL
What is CVE-2026-63764?
The lmdeploy product from InternLM is affected by a server-side request forgery vulnerability that enables unauthenticated attackers to access sensitive internal services. By manipulating the 'image_url' parameter, attackers can redirect requests to targeted internal endpoints, including loopback addresses and cloud metadata services. This redirection is facilitated by the server’s failure to re-validate each redirection, thus bypassing existing safety mechanisms. As a result, attackers can exploit this flaw to extract sensitive data or compromise the integrity of the system.
Affected Version(s)
lmdeploy 648df3b
