Tag
medium
advisory
LMDeploy Hardcoded trust_remote_code Enables Remote Code Execution (CVE-2026-46517)
2 rules 2 TTPs 1 IOCLMDeploy <= 0.12.3 is vulnerable to remote code execution (CVE-2026-46517) because it hardcodes `trust_remote_code=True` when calling `transformers.AutoConfig.from_pretrained()`, allowing a malicious Hugging Face repository to execute arbitrary Python code when loaded without user opt-out.
transformers +1
remote code execution
supply chain
lmdeploy
2r
2t
1i
high
advisory
LMDeploy Vision-Language Module SSRF Vulnerability
2 rules 1 TTP 1 CVE 4 IOCsA server-side request forgery (SSRF) vulnerability exists in LMDeploy's vision-language module, allowing attackers to access cloud metadata services and internal networks by exploiting the lack of URL validation in the `load_image()` function.
LMDeploy
ssrf
vulnerability
2r
1t
1c
4i