THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3hmm-rh5q-gwwr (high) — LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading

[GHSA] GHSA-3hmm-rh5q-gwwr (high) — LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading

medgithub_advisoriesPublished 2026-09-18

GHSA-3hmm-rh5q-gwwr Severity: high CVE: CVE-2026-33625

LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading

### Summary

lmdeploy <= latest contains a code injection vulnerability in `lmdeploy/pytorch/config.py` line 620 that allows an attacker to execute arbitrary Python code by publishing a malicious HuggingFace model with a crafted `quant

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3hmm-rh5q-gwwr