<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:01:05 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-67729 — lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-67729</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; InternLM lmdeploy&lt;/p&gt;
&lt;p&gt;LMDeploy is a toolkit for compressing, deploying, and serving LLMs. Prior to version 0.11.1, an insecure deserialization vulnerability exists in lmdeploy where torch.load() is called without the weights_only=True parameter when loading model checkpoint files. This allows an attacker to execute arbitrary code on the victim&amp;#39;s machine when they load a malicious .bin or .pt model file. This issue has been patched in version 0.11.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; InternLM lmdeploy&lt;/p&gt;
&lt;p&gt;LMDeploy is a toolkit for compressing, deploying, and serving LLMs. Prior to version 0.11.1, an insecure deserialization vulnerability exists in lmdeploy where torch.load() is called without the weights_only=True parameter when loading model checkpoint files. This allows an attacker to execute arbitrary code on the victim&amp;#39;s machine when they load a malicious .bin or .pt model file. This issue has been patched in version 0.11.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-67729</guid>
    </item>
    <item>
      <title>GHSA-9pf3-7rrr-x5jh — lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9pf3-7rrr-x5jh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lmdeploy&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;An insecure deserialization vulnerability exists in lmdeploy where `torch.load()` is called without the `weights_only=True` parameter when loading model checkpoint files. This allows an attacker to execute arbitrary code on the victim&amp;#39;s machine when they load a malicious `.bin` or `.pt` model file.&lt;/p&gt;
&lt;p&gt;**CWE:** CWE-502 - Deserialization of Untrusted Data&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;Several locations in lmdeploy use `torch.load()` without the recommended `weights_only=True` security parameter. PyTorch&amp;#39;s `torch.load()` uses Python&amp;#39;s pickle module internally, which can execute arbitrary code during deserialization.&lt;/p&gt;
&lt;p&gt;### Vulnerable Locations&lt;/p&gt;
&lt;p&gt;**1. `lmdeploy/vl/model/utils.py` (Line 22)**&lt;/p&gt;
&lt;p&gt;```python
def load_weight_ckpt(ckpt: str) -&amp;gt; Dict[str, torch.Tensor]:
    &amp;#34;&amp;#34;&amp;#34;Load checkpoint.&amp;#34;&amp;#34;&amp;#34;
    if ckpt.endswith(&amp;#39;.safetensors&amp;#39;):
        return load_file(ckpt)  # Safe - uses safetensors
    else:
        return torch.load(ckpt)  # ← VULNERABLE: no weights_only=True
```&lt;/p&gt;
&lt;p&gt;**2. `lmdeploy/turbomind/deploy/loader.py` (Line 122)**&lt;/p&gt;
&lt;p&gt;```python
class PytorchLoader(BaseLoader):
    def items(self):
        params = defaultdict(dict)
        for shard in self.shards:
            misc = {}
            tmp = torch.load(shard, map_location=&amp;#39;cpu&amp;#39;)  # ← VULNERABLE
```&lt;/p&gt;
&lt;p&gt;**Additional vulnerable locations:**
- `lmdeploy/lite/apis/kv_qparams.py:129-130`
- `lmdeploy/lite/apis/smooth_quant.py:61`
- `lmdeploy/lite/apis/auto_awq.py:101`
- `lmdeploy/lite/apis/get_small_sharded_hf.py:41`&lt;/p&gt;
&lt;p&gt;### Note: Secure Pattern…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lmdeploy&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;An insecure deserialization vulnerability exists in lmdeploy where `torch.load()` is called without the `weights_only=True` parameter when loading model checkpoint files. This allows an attacker to execute arbitrary code on the victim&amp;#39;s machine when they load a malicious `.bin` or `.pt` model file.&lt;/p&gt;
&lt;p&gt;**CWE:** CWE-502 - Deserialization of Untrusted Data&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;Several locations in lmdeploy use `torch.load()` without the recommended `weights_only=True` security parameter. PyTorch&amp;#39;s `torch.load()` uses Python&amp;#39;s pickle module internally, which can execute arbitrary code during deserialization.&lt;/p&gt;
&lt;p&gt;### Vulnerable Locations&lt;/p&gt;
&lt;p&gt;**1. `lmdeploy/vl/model/utils.py` (Line 22)**&lt;/p&gt;
&lt;p&gt;```python
def load_weight_ckpt(ckpt: str) -&amp;gt; Dict[str, torch.Tensor]:
    &amp;#34;&amp;#34;&amp;#34;Load checkpoint.&amp;#34;&amp;#34;&amp;#34;
    if ckpt.endswith(&amp;#39;.safetensors&amp;#39;):
        return load_file(ckpt)  # Safe - uses safetensors
    else:
        return torch.load(ckpt)  # ← VULNERABLE: no weights_only=True
```&lt;/p&gt;
&lt;p&gt;**2. `lmdeploy/turbomind/deploy/loader.py` (Line 122)**&lt;/p&gt;
&lt;p&gt;```python
class PytorchLoader(BaseLoader):
    def items(self):
        params = defaultdict(dict)
        for shard in self.shards:
            misc = {}
            tmp = torch.load(shard, map_location=&amp;#39;cpu&amp;#39;)  # ← VULNERABLE
```&lt;/p&gt;
&lt;p&gt;**Additional vulnerable locations:**
- `lmdeploy/lite/apis/kv_qparams.py:129-130`
- `lmdeploy/lite/apis/smooth_quant.py:61`
- `lmdeploy/lite/apis/auto_awq.py:101`
- `lmdeploy/lite/apis/get_small_sharded_hf.py:41`&lt;/p&gt;
&lt;p&gt;### Note: Secure Pattern…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9pf3-7rrr-x5jh</guid>
    </item>
  </channel>
</rss>
