Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

InternLM — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting InternLM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

InternLM is a large language model developed for enterprise AI applications and research purposes. Historically, vulnerabilities associated with InternLM include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation, often stemming from input validation flaws and insecure API implementations. The model has accumulated four CVEs to date, with security researchers identifying risks in its web interface and model deployment configurations. While no major public security incidents have been reported, the presence of multiple CVEs suggests ongoing challenges in securing large language model deployments, particularly around user input handling and access control mechanisms.

Top products by InternLM: LMDeploy MindSearch
CVE ID Title CVSS Severity Published
CVE-2026-105135 InternLM MindSearch Planner Agent graph.py ExecutionAction.run code injection — MindSearch CWE-94 10.0 Critical 2026-10-04
CVE-2026-33625 LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading — lmdeploy CWE-400 8.8 High 2026-09-18
CVE-2025-66455 LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py — lmdeploy CWE-502 9.8 Critical 2026-09-18
CVE-2026-92983 InternLM LMDeploy through 0.17.0 Memory Exhaustion via Session ID Mismatch — lmdeploy CWE-772 7.5 High 2026-09-17
CVE-2026-92971 InternLM LMDeploy through 0.17.0 Assertion Denial of Service — lmdeploy CWE-617 7.5 High 2026-09-17
CVE-2025-59953 LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy — lmdeploy CWE-502 9.8 Critical 2026-09-16
CVE-2026-76850 LMDeploy Remote Code Execution via Unsafe Pickle Deserialization in the Disaggregated Serving Peer Connector — lmdeploy CWE-502 9.8 Critical 2026-08-19
CVE-2026-63764 LMDeploy Server-Side Request Forgery via HTTP Redirect Bypass — lmdeploy CWE-918 8.6 High 2026-07-21
CVE-2026-46517 LMDeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out — lmdeploy CWE-94 7.8 High 2026-06-09
CVE-2026-46432 LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization — lmdeploy CWE-94 7.8 High 2026-06-09
CVE-2026-33626 LMDeploy Vulnerable to Server-Side Request Forgery (SSRF) via Vision-Language Image Loading — lmdeploy CWE-918 7.5 High 2026-04-20
CVE-2025-67729 lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load() — lmdeploy CWE-502 8.8 High 2025-12-26
CVE-2025-3163 InternLM LMDeploy conf.py open code injection — LMDeploy CWE-94 5.3 Medium 2025-04-03
CVE-2025-3162 InternLM LMDeploy PT File utils.py load_weight_ckpt deserialization — LMDeploy CWE-502 5.3 Medium 2025-04-03

This page lists every published CVE security advisory associated with InternLM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.