{"id":"CVE-2026-33625","published":"2026-09-18T18:17:06.640","lastModified":"2026-09-24T21:25:27.050","description":"LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contain a code injection vulnerability in `lmdeploy/pytorch/config.py` line 620 that allows an attacker to execute arbitrary Python code by publishing a malicious HuggingFace model with a crafted `quantization_config.quant_dtype` value. When a user loads the model with lmdeploy, the `quant_dtype` is passed to `eval(f'torch.{quant_dtype}')` without any validation. Version 0.12.3 contains a patch.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-400"],"vendors":[],"products":[],"references":[{"url":"https://github.com/InternLM/lmdeploy/releases/tag/v0.12.3","tags":[]},{"url":"https://github.com/InternLM/lmdeploy/security/advisories/GHSA-3hmm-rh5q-gwwr","tags":[]},{"url":"https://github.com/InternLM/lmdeploy/security/advisories/GHSA-3hmm-rh5q-gwwr","tags":[]}],"exploitRefs":[{"url":"https://github.com/InternLM/lmdeploy/releases/tag/v0.12.3","tags":[]},{"url":"https://github.com/InternLM/lmdeploy/security/advisories/GHSA-3hmm-rh5q-gwwr","tags":[]},{"url":"https://github.com/InternLM/lmdeploy/security/advisories/GHSA-3hmm-rh5q-gwwr","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows an attacker to execute arbitrary Python code by crafting a specific `quantization_config.quant_dtype` value, leading to remote code execution.","exploitability":"Exploitation is relatively straightforward given the attacker can control the `quantization_config.quant_dtype` value. The precondition is the user must load the malicious model.","blast_radius":"If exploited, the impact could be severe, potentially allowing full control over the system hosting the `lmdeploy` service.","remediation":"Upgrade to version 0.12.3 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","python-code-execution","remote-code-execution","lmdploy","security-vulnerability"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:22:42.997Z"}}