id: PYSEC-2026-1577 published: "2026-07-07T16:02:50.626227Z" modified: "2026-07-07T17:24:35.103862Z" aliases: - CVE-2025-3162 - GHSA-7vc5-mjwp-c8fq summary: LMDeploy Improper Input Validation Vulnerability details: A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file lmdeploy/lmdeploy/vl/model/utils.py of the component PT File Handler. The manipulation leads to deserialization. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. affected: - package: name: lmdeploy ecosystem: PyPI purl: pkg:pypi/lmdeploy ranges: - type: ECOSYSTEM events: - introduced: "0" - last_affected: 0.7.1 versions: - 0.0.10 - 0.0.11 - 0.0.12 - 0.0.13 - 0.0.14 - 0.1.0 - 0.2.0 - 0.2.1 - 0.2.2 - 0.2.3 - 0.2.4 - 0.2.5 - 0.2.6 - 0.3.0 - 0.4.0 - 0.4.1 - 0.4.2 - 0.5.0 - 0.5.1 - 0.5.2 - 0.5.2.post1 - 0.5.3 - 0.6.0 - 0.6.0a0 - 0.6.1 - 0.6.2 - 0.6.2.post1 - 0.6.3 - 0.6.4 - 0.6.5 - 0.7.0 - 0.7.0.post1 - 0.7.0.post2 - 0.7.0.post3 - 0.7.1 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2025-3162 - type: WEB url: https://github.com/InternLM/lmdeploy/issues/3255 - type: WEB url: "https://github.com/InternLM/lmdeploy/issues/3255#issue-2918985270" - type: PACKAGE url: https://github.com/InternLM/lmdeploy - type: WEB url: https://vuldb.com/?ctiid.303108 - type: WEB url: https://vuldb.com/?id.303108 - type: WEB url: https://vuldb.com/?submit.542520 - type: PACKAGE url: https://pypi.org/project/lmdeploy - type: ADVISORY url: https://github.com/advisories/GHSA-7vc5-mjwp-c8fq severity: - type: CVSS_V3 score: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L - type: CVSS_V4 score: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N