CVE-2026-46517: Internlm Lmdeploy
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardcoded "trust_remote_code=True" enables HF supply-chain RCE without user opt-in. Version 0.13.0 patches the issue.
Affected products
- Internlm Lmdeploy: up to and including 0.12.3
Published 2026-06-10. Last modified 2026-08-31.