lmdeploy@0.9.0 vulnerabilities

A toolset for compressing, deploying and serving LLM

Direct Vulnerabilities

Known vulnerabilities in the lmdeploy package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Arbitrary Code Injection

Affected versions of this package are vulnerable to Arbitrary Code Injection through the Open function of the file lmdeploy/docs/en/conf.py. An attacker can manipulate the input to execute arbitrary code by crafting malicious input that is processed by this function.

How to fix Arbitrary Code Injection?

There is no fixed version for lmdeploy.

[0,)
  • M
Improper Input Validation

Affected versions of this package are vulnerable to Improper Input Validation via the load_weight_ckpt function. An attacker can manipulate the deserialization process by providing malicious input to the PT File Handler component.

How to fix Improper Input Validation?

There is no fixed version for lmdeploy.

[0,)