Mark RadarMARK RADAR
EN

LMDeploy SSRF Flaw Exploited Within 13 Hours of Disclosure

1 reports · First detected 2026-04-27 · Last active 2026-04-27

LMDeploy, developed by InternLM, is a widely used deployment and inference tool for large language models that handles text and image requests. The server-side request forgery vulnerability tracked as CVE-2026-33626 allows unauthorized attackers to use the image_url field to trick servers into connecting to internal systems or cloud metadata services, potentially exposing credentials and sensitive information.

CVE-2026-33626, disclosed in 2026, was observed being exploited in real-world attacks less than 13 hours after the security advisory was published, showing how quickly the vulnerability details were turned into an intrusion method. InternLM has patched the flaw in LMDeploy 0.12.3. Cybersecurity experts recommend upgrading immediately to version 0.12.3 or later and reviewing service access logs and cloud credentials for anomalies.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR