HomeSecurityLMDeploy: Vulnerability exploited 13 hours after disclosure

LMDeploy: Vulnerability Exploited 13 Hours After Disclosure

A critical vulnerability in LMDeploy, an open-source tool for compressing, deploying, and serving large language models, was actively exploited by attackers just 13 hours after it was publicly disclosed. The vulnerability, CVE-2026-33626, with a CVSS score of 7.5, is a serious example of how quickly cyberattackers are exploiting new vulnerabilities in the artificial intelligence space.

LMDeploy

The vulnerability was identified in the vision-language module and is related to Server-Side Request Forgery (SSRF) attacks that allow access to sensitive data.

According to the official announcement from the project maintainers, the load_image() function in the lmdeploy/vl/utils.py file retrieves arbitrary URLs without validating whether those URLs point to internal or private IP addresses. This lack of input validation allows attackers to gain access to cloud metadata services, internal networks, and sensitive resources.

See also: Marimo: Vulnerability exploited within 10 hours of publication

Technical details of the vulnerability CVE-2026-33626

The vulnerability affects all versions of LMDeploy prior to 0.12.3, which includes the fix. Researcher Igor Stepansky from Orca Security was credited with discovering and reporting the bug. Successful exploitation of the vulnerability could allow an attacker to steal cloud credentials, reach internal services that are not exposed to the internet, perform port scanning on internal networks, and create opportunities for lateral movement.

Cloud security firm Sysdig reported that it detected the first attempt to exploit LMDeployagainst its honeypot systems within 12 hours and 31 minutes of the vulnerability being published on GitHub. The exploit attempt originated from the IP address 103.116.72.119 and occurred on April 22, 2026 at 03:35 UTC.

The attacker didn't just validate the error. Instead, over the course of an eight-minute, he used the vision-language image loader as a generic HTTP SSRF primitive to port scan the internal network behind the model server. Targets included the AWS Instance Metadata Service (IMDS), Redis, MySQL, a secondary HTTP management interface, and an out-of-band (OOB) DNS endpoint for data extraction.

See also: Prompt Injection Flaw in Vanna AI Exposes Databases to RCE Attacks

LMDeploy: Vulnerability Exploited 13 Hours After Disclosure

Attack pattern and attacker strategy

The adversary’s actions unfolded in 10 distinct requests in three phases, with the requests alternating between vision language models such as internlm-xcomposer2 and OpenGVLab/InternVL2-8B to avoid attention. The first phase targeted AWS IMDS and Redis instances on the server. The second phase involved an exit test with an OOB DNS callback to requestrepo.com to confirm that the SSRF vulnerability can reach arbitrary external hosts. The third phase involved a port scan of the loopback interface 127.0.0.1.

The findings are yet another reminder of how closely threat actors are tracking new vulnerability disclosures and exploiting them before downstream users can apply patches, even in cases where proof-of-concept (PoC) exploits are not available at the time of the attack. CVE-2026-33626 fits a pattern that has been observed repeatedly in the AI-infrastructure space over the past six months: critical vulnerabilities in inference servers, model gateways, and agent orchestration tools are weaponized within hours of security advisories being published.

See also: ShowDoc: Critical RCE vulnerability actively exploited

LMDeploy: Vulnerability Exploited 13 Hours After Disclosure

Organizations using LMDeploy in production environments should immediately update to version 0.12.3 or later, implement strict firewall rules, and enable authentication layers on all endpoints.

According to The Hacker News, this incident highlights the growing threat facing artificial intelligence infrastructure and the need for proactive security measures in the rapidly evolving field of AI.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS