Internlm maintains a focused portfolio centered on LMDeploy, a model-deployment framework for large language models, with a modestly represented vulnerability footprint that reflects the security concerns of serving inference workloads. The durable signal centers on application-layer input-handling and code-execution risks, with observed weaknesses including untrusted deserialization, code injection, input validation issues, injection flaws, and server-side request forgery that are characteristic of frameworks bridging external requests to model inference pipelines. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Internlm over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33626HIGH LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Server-Side Request Forgery (SSRF) vulnerability in LMDeploy's | Apr 20, 2026 | 7.5 | 70 | NO | YES |
CVE-2026-63764HIGH LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, | Jul 21, 2026 | 8.6 | 37 | NO | NO |
CVE-2025-67729HIGH LMDeploy is a toolkit for compressing, deploying, and serving LLMs. Prior to version 0.11.1, an insecure deserialization vulnerability exists in lmdeploy where torch.load() is call | Dec 26, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-3163HIGH A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerability is the function Open of the file lmdeploy/docs/en/conf. | Apr 3, 2025 | 7.8 | 22 | NO | NO |
CVE-2025-3162HIGH A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file lmdeploy/lmdeploy/vl/model/uti | Apr 3, 2025 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Internlm.
Media articles that mention a CVE ID that affects a product developed by Internlm — matched by CVE ID, not by vendor name.