Vendor
critical
advisory
Remote Code Execution in LMDeploy via Unsafe Pickle Deserialization
2 TTPs 1 CVEThe LMDeploy library insecurely deserializes untrusted peer-to-peer messages using Python's pickle module, allowing unauthenticated remote attackers to achieve remote code execution by providing a malicious ZMQ endpoint.
LMDeploy
2t
1c
critical
advisory
CVE-2026-63764: Server-Side Request Forgery in lmdeploy OpenAI-Compatible API Server
1 rule 1 TTP 1 CVEAn unauthenticated server-side request forgery (SSRF) vulnerability, CVE-2026-63764, exists in lmdeploy's OpenAI-compatible API server, allowing attackers to access internal services and cloud metadata by submitting a crafted image_url that redirects to internal targets.
lmdeploy's OpenAI-compatible API server
server-side-request-forgery
ssrf
vulnerability
api
cloud-security
1r
1t
1c
high
advisory
LMDeploy Vision-Language Module SSRF Vulnerability
2 rules 1 TTP 1 CVE 4 IOCsA server-side request forgery (SSRF) vulnerability exists in LMDeploy's vision-language module, allowing attackers to access cloud metadata services and internal networks by exploiting the lack of URL validation in the `load_image()` function.
LMDeploy
ssrf
vulnerability
2r
1t
1c
4i