← Vulnerability feed

Vulnerability record · CVE-2025-3162 · published 3 April 2025

CVE-2025-3162: Internlm lmdeploy improper input validation vulnerability

IInternlm · Lmdeploy

A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file lmdeploy/lmdeploy/vl/model/utils.py of the component PT File Handler. The manipulation leads to deserialization. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

4.8 CVSS 4.0 Medium EPSS 0.32% · top 77.1% CWE-20 · Improper input validationCWE-502 · Deserialization of untrusted data
4.8CVSS 4.0 base score, v2 4.3
0.32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 3 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file lmdeploy/lmdeploy/vl/model/utils.py of the component PT File Handler. The manipulation leads to deserialization. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/InternLM/lmdeploy/issues/3255 ExploitIssue TrackingVendor Advisory
https://github.com/InternLM/lmdeploy/issues/3255#issue-2918985270 ExploitIssue TrackingVendor Advisory
https://vuldb.com/?ctiid.303108 Permissions RequiredVDB Entry
https://vuldb.com/?id.303108 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.542520 Third Party AdvisoryVDB Entry
https://github.com/InternLM/lmdeploy/issues/3255 ExploitIssue TrackingVendor Advisory

Track CVE-2025-3162 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-67729Internlm lmdeploy deserialization of untrusted data vulnerabilityLMDeploy is a toolkit for compressing, deploying, and serving LLMs. Prior to version 0.11.1, an insecure deserialization vulnerability exists in lmde…EPSS 0.60%7.7CVE-2026-63764Internlm lmdeploy server-side request forgery (ssrf) vulnerabilityLMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within t…EPSS 0.51%7.5CVE-2026-33626LMDeploy vision-language load_image() SSRF via unvalidated URLsLMDeploy versions before 0.12.3 have a server-side request forgery flaw in the vision-language module. The load_image() function in lmdeploy/vl/utils…EPSS 1.5%analysed4.8CVE-2025-3163Internlm lmdeploy injection vulnerabilityA vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerability is the function Open of …EPSS 0.37%9.5CVE-2026-88771Citrix NetScaler Improper Input Validation VulnerabilityImproper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-…KEV9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 1.1%8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed

Source: NIST National Vulnerability Database (record CVE-2025-3162), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.