LMDeploy SSRF Flaw Exploited Within 13 Hours of Disclosure
LMDeploy, developed by InternLM, is a widely used deployment and inference tool for large language models that handles text and image requests. The server-side request forgery vulnerability tracked as CVE-2026-33626 allows unauthorized attackers to use the image_url field to trick servers into connecting to internal systems or cloud metadata services, potentially exposing credentials and sensitive information.
CVE-2026-33626, disclosed in 2026, was observed being exploited in real-world attacks less than 13 hours after the security advisory was published, showing how quickly the vulnerability details were turned into an intrusion method. InternLM has patched the flaw in LMDeploy 0.12.3. Cybersecurity experts recommend upgrading immediately to version 0.12.3 or later and reviewing service access logs and cloud credentials for anomalies.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.