<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 14:34:04 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-46517 — LMDeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-46517</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; InternLM lmdeploy&lt;/p&gt;
&lt;p&gt;LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardcoded &amp;#34;trust_remote_code=True&amp;#34; enables HF supply-chain RCE without user opt-in. Version 0.13.0 patches the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; InternLM lmdeploy&lt;/p&gt;
&lt;p&gt;LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardcoded &amp;#34;trust_remote_code=True&amp;#34; enables HF supply-chain RCE without user opt-in. Version 0.13.0 patches the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-46517</guid>
    </item>
    <item>
      <title>GHSA-9xq9-36w5-q796 — lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9xq9-36w5-q796</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lmdeploy&lt;/p&gt;
&lt;p&gt;&amp;gt; ## 📋 Reframing (2026-05-02): implicit unsafe remote-code path, not &amp;#34;supply-chain&amp;#34;
&amp;gt;
&amp;gt; The accurate description of this vulnerability is:
&amp;gt; **&amp;#34;`get_model_arch` and related helpers hardcode `trust_remote_code=True`
&amp;gt; with no opt-out, creating an implicit unsafe remote-code load path
&amp;gt; on every model fetch.&amp;#34;**
&amp;gt;
&amp;gt; What this report does NOT claim:
&amp;gt; * It is NOT a network-attack RCE — the user supplies the model
&amp;gt;   reference; LMDeploy honors it.
&amp;gt; * It is NOT a &amp;#34;supply chain&amp;#34; CVE in the classical sense (where a
&amp;gt;   benign upstream is compromised) — the user explicitly types the
&amp;gt;   repo name.
&amp;gt;
&amp;gt; What this report DOES claim:
&amp;gt; * Other inference frameworks (vLLM, TGI, Hugging Face transformers
&amp;gt;   itself) all expose `--trust-remote-code` as **opt-in** so that
&amp;gt;   users who consciously load known-safe repos can opt in, while
&amp;gt;   users following a tutorial cannot accidentally execute attacker
&amp;gt;   Python by typing a wrong repo name.
&amp;gt; * LMDeploy&amp;#39;s hardcoded True is an **implicit** trust-boundary
&amp;gt;   override that violates HF Transformers&amp;#39; default-secure stance
&amp;gt;   (`trust_remote_code=False` since transformers ≥ 4.30).
&amp;gt; * The fix is a one-line CLI flag (`--trust-remote-code`) defaulting
&amp;gt;   False, threaded through the three sites, matching the rest of
&amp;gt;   the ecosystem.
&amp;gt;
&amp;gt; Severity should be assessed as **hardening / safe-by-default**,
&amp;gt; not as full unauthenticated RCE. CVSS revised to **5.5 Medium**
&amp;gt; (`AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H` × user-must-load qualifier).
&amp;gt;
&amp;gt; Runtim…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lmdeploy&lt;/p&gt;
&lt;p&gt;&amp;gt; ## 📋 Reframing (2026-05-02): implicit unsafe remote-code path, not &amp;#34;supply-chain&amp;#34;
&amp;gt;
&amp;gt; The accurate description of this vulnerability is:
&amp;gt; **&amp;#34;`get_model_arch` and related helpers hardcode `trust_remote_code=True`
&amp;gt; with no opt-out, creating an implicit unsafe remote-code load path
&amp;gt; on every model fetch.&amp;#34;**
&amp;gt;
&amp;gt; What this report does NOT claim:
&amp;gt; * It is NOT a network-attack RCE — the user supplies the model
&amp;gt;   reference; LMDeploy honors it.
&amp;gt; * It is NOT a &amp;#34;supply chain&amp;#34; CVE in the classical sense (where a
&amp;gt;   benign upstream is compromised) — the user explicitly types the
&amp;gt;   repo name.
&amp;gt;
&amp;gt; What this report DOES claim:
&amp;gt; * Other inference frameworks (vLLM, TGI, Hugging Face transformers
&amp;gt;   itself) all expose `--trust-remote-code` as **opt-in** so that
&amp;gt;   users who consciously load known-safe repos can opt in, while
&amp;gt;   users following a tutorial cannot accidentally execute attacker
&amp;gt;   Python by typing a wrong repo name.
&amp;gt; * LMDeploy&amp;#39;s hardcoded True is an **implicit** trust-boundary
&amp;gt;   override that violates HF Transformers&amp;#39; default-secure stance
&amp;gt;   (`trust_remote_code=False` since transformers ≥ 4.30).
&amp;gt; * The fix is a one-line CLI flag (`--trust-remote-code`) defaulting
&amp;gt;   False, threaded through the three sites, matching the rest of
&amp;gt;   the ecosystem.
&amp;gt;
&amp;gt; Severity should be assessed as **hardening / safe-by-default**,
&amp;gt; not as full unauthenticated RCE. CVSS revised to **5.5 Medium**
&amp;gt; (`AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H` × user-must-load qualifier).
&amp;gt;
&amp;gt; Runtim…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9xq9-36w5-q796</guid>
    </item>
  </channel>
</rss>
