PT-2025-14770 · Unknown · Internlm Lmdeploy

Ybdesire

·

Published

2025-04-03

·

Updated

2025-04-24

·

CVE-2025-3162

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions InternLM LMDeploy versions up to 0.7.1
Description A critical issue was found in InternLM LMDeploy, affecting the function load weight ckpt of the file lmdeploy/lmdeploy/vl/model/utils.py in the component PT File Handler. The manipulation leads to deserialization, and attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
Recommendations To resolve the issue, update to a version later than 0.7.1. As a temporary workaround, consider disabling the load weight ckpt function until a patch is available. Restrict access to the PT File Handler component to minimize the risk of exploitation.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-3162
GHSA-7VC5-MJWP-C8FQ

Affected Products

Internlm Lmdeploy