lmdeploy@0.6.5 vulnerabilities

A toolset for compressing, deploying and serving LLM

Direct Vulnerabilities

Known vulnerabilities in the lmdeploy package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Improper Input Validation

Affected versions of this package are vulnerable to Improper Input Validation via the load_weight_ckpt function. An attacker can manipulate the deserialization process by providing malicious input to the PT File Handler component.

How to fix Improper Input Validation?

There is no fixed version for lmdeploy.

[0,)