Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m549-qq94-fvhg | LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization |
Wed, 10 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Internlm
Internlm lmdeploy |
|
| Vendors & Products |
Internlm
Internlm lmdeploy |
Tue, 09 Jun 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDeploy is vulnerable to arbitrary code execution through hardcoded "trust_remote_code=True" in multiple HuggingFace model-loading call sites. At time of publication, there are no publicly available patches. | |
| Title | LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-11T03:55:31.478Z
Reserved: 2026-05-13T22:18:22.830Z
Link: CVE-2026-46432
Updated: 2026-06-10T12:58:07.041Z
Status : Deferred
Published: 2026-06-10T00:16:53.557
Modified: 2026-06-10T20:19:06.020
Link: CVE-2026-46432
No data.
OpenCVE Enrichment
Updated: 2026-06-10T02:45:15Z
Github GHSA