Server-Side Request Forgery Vulnerability in lmdeploy by InternLM
CVE-2026-63764
Key Information:
Badges
What is CVE-2026-63764?
The lmdeploy product from InternLM is affected by a server-side request forgery vulnerability that enables unauthenticated attackers to access sensitive internal services. By manipulating the 'image_url' parameter, attackers can redirect requests to targeted internal endpoints, including loopback addresses and cloud metadata services. This redirection is facilitated by the server’s failure to re-validate each redirection, thus bypassing existing safety mechanisms. As a result, attackers can exploit this flaw to extract sensitive data or compromise the integrity of the system.
Affected Version(s)
lmdeploy 0 <= 0.14.0
lmdeploy 03c313006d17cc3feae86b633c44206a997c44db
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
