CVE-2026-46432: Internlm Lmdeploy

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDeploy is vulnerable to arbitrary code execution through hardcoded "trust_remote_code=True" in multiple HuggingFace model-loading call sites. At time of publication, there are no publicly available patches.

Affected products

  • Internlm Lmdeploy: up to and including 0.12.3

Published 2026-06-10. Last modified 2026-07-23.