lmdeploy Package Vulnerability: Critical Remote Code Execution Risk
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- lmdeploy (pypi)
- Affected versions
- <= 0.12.2 or >= 0.0.10, <= 0.0.10 or >= 0.0.11, <= 0.0.11 or >= 0.0.12, <= 0.0.12 or >= 0.0.13, <= 0.0.13 or >= 0.0.14, <= 0.0.14 or >= 0.1.0, <= 0.1.0 or >= 0.10.0, <= 0.10.0 or >= 0.10.1, <= 0.10.1 or >= 0.10.2, <= 0.10.2 or >= 0.11.0, <= 0.11.0 or >= 0.11.1, <= 0.11.1 or >= 0.12.0, <= 0.12.0 or >= 0.12.1, <= 0.12.1 or >= 0.12.2, <= 0.12.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.2.5, <= 0.2.5 or >= 0.2.6, <= 0.2.6 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.5.0, <= 0.5.0 or >= 0.5.1, <= 0.5.1 or >= 0.5.2, <= 0.5.2 or >= 0.5.2.post1, <= 0.5.2.post1 or >= 0.5.3, <= 0.5.3 or >= 0.6.0, <= 0.6.0 or >= 0.6.0a0, <= 0.6.0a0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.2.post1, <= 0.6.2.post1 or >= 0.6.3, <= 0.6.3 or >= 0.6.4, <= 0.6.4 or >= 0.6.5, <= 0.6.5 or >= 0.7.0, <= 0.7.0 or >= 0.7.0.post1, <= 0.7.0.post1 or >= 0.7.0.post2, <= 0.7.0.post2 or >= 0.7.0.post3, <= 0.7.0.post3 or >= 0.7.1, <= 0.7.1 or >= 0.7.2, <= 0.7.2 or >= 0.7.2.post1, <= 0.7.2.post1 or >= 0.7.3, <= 0.7.3 or >= 0.8.0, <= 0.8.0 or >= 0.9.0, <= 0.9.0 or >= 0.9.1, <= 0.9.1 or >= 0.9.2, <= 0.9.2 or >= 0.9.2.post1, <= 0.9.2.post1 or <= 0.7.1 or >= 0.0.10, <= 0.0.10 or >= 0.0.11, <= 0.0.11 or >= 0.0.12, <= 0.0.12 or >= 0.0.13, <= 0.0.13 or >= 0.0.14, <= 0.0.14 or >= 0.1.0, <= 0.1.0 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.2.5, <= 0.2.5 or >= 0.2.6, <= 0.2.6 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.5.0, <= 0.5.0 or >= 0.5.1, <= 0.5.1 or >= 0.5.2, <= 0.5.2 or >= 0.5.2.post1, <= 0.5.2.post1 or >= 0.5.3, <= 0.5.3 or >= 0.6.0, <= 0.6.0 or >= 0.6.0a0, <= 0.6.0a0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.2.post1, <= 0.6.2.post1 or >= 0.6.3, <= 0.6.3 or >= 0.6.4, <= 0.6.4 or >= 0.6.5, <= 0.6.5 or >= 0.7.0, <= 0.7.0 or >= 0.7.0.post1, <= 0.7.0.post1 or >= 0.7.0.post2, <= 0.7.0.post2 or >= 0.7.0.post3, <= 0.7.0.post3 or >= 0.7.1, <= 0.7.1 or < 0.11.1 or >= 0.0.10, <= 0.0.10 or >= 0.0.11, <= 0.0.11 or >= 0.0.12, <= 0.0.12 or >= 0.0.13, <= 0.0.13 or >= 0.0.14, <= 0.0.14 or >= 0.1.0, <= 0.1.0 or >= 0.10.0, <= 0.10.0 or >= 0.10.1, <= 0.10.1 or >= 0.10.2, <= 0.10.2 or >= 0.11.0, <= 0.11.0 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.2.5, <= 0.2.5 or >= 0.2.6, <= 0.2.6 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.5.0, <= 0.5.0 or >= 0.5.1, <= 0.5.1 or >= 0.5.2, <= 0.5.2 or >= 0.5.2.post1, <= 0.5.2.post1 or >= 0.5.3, <= 0.5.3 or >= 0.6.0, <= 0.6.0 or >= 0.6.0a0, <= 0.6.0a0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.2.post1, <= 0.6.2.post1 or >= 0.6.3, <= 0.6.3 or >= 0.6.4, <= 0.6.4 or >= 0.6.5, <= 0.6.5 or >= 0.7.0, <= 0.7.0 or >= 0.7.0.post1, <= 0.7.0.post1 or >= 0.7.0.post2, <= 0.7.0.post2 or >= 0.7.0.post3, <= 0.7.0.post3 or >= 0.7.1, <= 0.7.1 or >= 0.7.2, <= 0.7.2 or >= 0.7.2.post1, <= 0.7.2.post1 or >= 0.7.3, <= 0.7.3 or >= 0.8.0, <= 0.8.0 or >= 0.9.0, <= 0.9.0 or >= 0.9.1, <= 0.9.1 or >= 0.9.2, <= 0.9.2 or >= 0.9.2.post1, <= 0.9.2.post1 or <= 0.12.3 or >= 0.0.10, <= 0.0.10 or >= 0.0.11, <= 0.0.11 or >= 0.0.12, <= 0.0.12 or >= 0.0.13, <= 0.0.13 or >= 0.0.14, <= 0.0.14 or >= 0.1.0, <= 0.1.0 or >= 0.10.0, <= 0.10.0 or >= 0.10.1, <= 0.10.1 or >= 0.10.2, <= 0.10.2 or >= 0.11.0, <= 0.11.0 or >= 0.11.1, <= 0.11.1 or >= 0.12.0, <= 0.12.0 or >= 0.12.1, <= 0.12.1 or >= 0.12.2, <= 0.12.2 or >= 0.12.3, <= 0.12.3 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.2.5, <= 0.2.5 or >= 0.2.6, <= 0.2.6 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.5.0, <= 0.5.0 or >= 0.5.1, <= 0.5.1 or >= 0.5.2, <= 0.5.2 or >= 0.5.2.post1, <= 0.5.2.post1 or >= 0.5.3, <= 0.5.3 or >= 0.6.0, <= 0.6.0 or >= 0.6.0a0, <= 0.6.0a0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.2.post1, <= 0.6.2.post1 or >= 0.6.3, <= 0.6.3 or >= 0.6.4, <= 0.6.4 or >= 0.6.5, <= 0.6.5 or >= 0.7.0, <= 0.7.0 or >= 0.7.0.post1, <= 0.7.0.post1 or >= 0.7.0.post2, <= 0.7.0.post2 or >= 0.7.0.post3, <= 0.7.0.post3 or >= 0.7.1, <= 0.7.1 or >= 0.7.2, <= 0.7.2 or >= 0.7.2.post1, <= 0.7.2.post1 or >= 0.7.3, <= 0.7.3 or >= 0.8.0, <= 0.8.0 or >= 0.9.0, <= 0.9.0 or >= 0.9.1, <= 0.9.1 or >= 0.9.2, <= 0.9.2 or >= 0.9.2.post1, <= 0.9.2.post1 or <= 0.7.1 or >= 0.0.10, <= 0.0.10 or >= 0.0.11, <= 0.0.11 or >= 0.0.12, <= 0.0.12 or >= 0.0.13, <= 0.0.13 or >= 0.0.14, <= 0.0.14 or >= 0.1.0, <= 0.1.0 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.2.5, <= 0.2.5 or >= 0.2.6, <= 0.2.6 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.5.0, <= 0.5.0 or >= 0.5.1, <= 0.5.1 or >= 0.5.2, <= 0.5.2 or >= 0.5.2.post1, <= 0.5.2.post1 or >= 0.5.3, <= 0.5.3 or >= 0.6.0, <= 0.6.0 or >= 0.6.0a0, <= 0.6.0a0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.2.post1, <= 0.6.2.post1 or >= 0.6.3, <= 0.6.3 or >= 0.6.4, <= 0.6.4 or >= 0.6.5, <= 0.6.5 or >= 0.7.0, <= 0.7.0 or >= 0.7.0.post1, <= 0.7.0.post1 or >= 0.7.0.post2, <= 0.7.0.post2 or >= 0.7.0.post3, <= 0.7.0.post3 or >= 0.7.1, <= 0.7.1 or < 0.13.0 or >= 0.0.10, <= 0.0.10 or >= 0.0.11, <= 0.0.11 or >= 0.0.12, <= 0.0.12 or >= 0.0.13, <= 0.0.13 or >= 0.0.14, <= 0.0.14 or >= 0.1.0, <= 0.1.0 or >= 0.10.0, <= 0.10.0 or >= 0.10.1, <= 0.10.1 or >= 0.10.2, <= 0.10.2 or >= 0.11.0, <= 0.11.0 or >= 0.11.1, <= 0.11.1 or >= 0.12.0, <= 0.12.0 or >= 0.12.1, <= 0.12.1 or >= 0.12.2, <= 0.12.2 or >= 0.12.3, <= 0.12.3 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.2.5, <= 0.2.5 or >= 0.2.6, <= 0.2.6 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.5.0, <= 0.5.0 or >= 0.5.1, <= 0.5.1 or >= 0.5.2, <= 0.5.2 or >= 0.5.2.post1, <= 0.5.2.post1 or >= 0.5.3, <= 0.5.3 or >= 0.6.0, <= 0.6.0 or >= 0.6.0a0, <= 0.6.0a0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.2.post1, <= 0.6.2.post1 or >= 0.6.3, <= 0.6.3 or >= 0.6.4, <= 0.6.4 or >= 0.6.5, <= 0.6.5 or >= 0.7.0, <= 0.7.0 or >= 0.7.0.post1, <= 0.7.0.post1 or >= 0.7.0.post2, <= 0.7.0.post2 or >= 0.7.0.post3, <= 0.7.0.post3 or >= 0.7.1, <= 0.7.1 or >= 0.7.2, <= 0.7.2 or >= 0.7.2.post1, <= 0.7.2.post1 or >= 0.7.3, <= 0.7.3 or >= 0.8.0, <= 0.8.0 or >= 0.9.0, <= 0.9.0 or >= 0.9.1, <= 0.9.1 or >= 0.9.2, <= 0.9.2 or >= 0.9.2.post1, <= 0.9.2.post1 or <= 0.7.1 or >= 0.0.10, <= 0.0.10 or >= 0.0.11, <= 0.0.11 or >= 0.0.12, <= 0.0.12 or >= 0.0.13, <= 0.0.13 or >= 0.0.14, <= 0.0.14 or >= 0.1.0, <= 0.1.0 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.2.5, <= 0.2.5 or >= 0.2.6, <= 0.2.6 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.5.0, <= 0.5.0 or >= 0.5.1, <= 0.5.1 or >= 0.5.2, <= 0.5.2 or >= 0.5.2.post1, <= 0.5.2.post1 or >= 0.5.3, <= 0.5.3 or >= 0.6.0, <= 0.6.0 or >= 0.6.0a0, <= 0.6.0a0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.2.post1, <= 0.6.2.post1 or >= 0.6.3, <= 0.6.3 or >= 0.6.4, <= 0.6.4 or >= 0.6.5, <= 0.6.5 or >= 0.7.0, <= 0.7.0 or >= 0.7.0.post1, <= 0.7.0.post1 or >= 0.7.0.post2, <= 0.7.0.post2 or >= 0.7.0.post3, <= 0.7.0.post3 or >= 0.7.1, <= 0.7.1 or < 0.11.1 or >= 0.0.10, <= 0.0.10 or >= 0.0.11, <= 0.0.11 or >= 0.0.12, <= 0.0.12 or >= 0.0.13, <= 0.0.13 or >= 0.0.14, <= 0.0.14 or >= 0.1.0, <= 0.1.0 or >= 0.10.0, <= 0.10.0 or >= 0.10.1, <= 0.10.1 or >= 0.10.2, <= 0.10.2 or >= 0.11.0, <= 0.11.0 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.2.5, <= 0.2.5 or >= 0.2.6, <= 0.2.6 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.5.0, <= 0.5.0 or >= 0.5.1, <= 0.5.1 or >= 0.5.2, <= 0.5.2 or >= 0.5.2.post1, <= 0.5.2.post1 or >= 0.5.3, <= 0.5.3 or >= 0.6.0, <= 0.6.0 or >= 0.6.0a0, <= 0.6.0a0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.2.post1, <= 0.6.2.post1 or >= 0.6.3, <= 0.6.3 or >= 0.6.4, <= 0.6.4 or >= 0.6.5, <= 0.6.5 or >= 0.7.0, <= 0.7.0 or >= 0.7.0.post1, <= 0.7.0.post1 or >= 0.7.0.post2, <= 0.7.0.post2 or >= 0.7.0.post3, <= 0.7.0.post3 or >= 0.7.1, <= 0.7.1 or >= 0.7.2, <= 0.7.2 or >= 0.7.2.post1, <= 0.7.2.post1 or >= 0.7.3, <= 0.7.3 or >= 0.8.0, <= 0.8.0 or >= 0.9.0, <= 0.9.0 or >= 0.9.1, <= 0.9.1 or >= 0.9.2, <= 0.9.2 or >= 0.9.2.post1, <= 0.9.2.post1 or <= 0.7.1 or >= 0.0.10, <= 0.0.10 or >= 0.0.11, <= 0.0.11 or >= 0.0.12, <= 0.0.12 or >= 0.0.13, <= 0.0.13 or >= 0.0.14, <= 0.0.14 or >= 0.1.0, <= 0.1.0 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.2.5, <= 0.2.5 or >= 0.2.6, <= 0.2.6 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.5.0, <= 0.5.0 or >= 0.5.1, <= 0.5.1 or >= 0.5.2, <= 0.5.2 or >= 0.5.2.post1, <= 0.5.2.post1 or >= 0.5.3, <= 0.5.3 or >= 0.6.0, <= 0.6.0 or >= 0.6.0a0, <= 0.6.0a0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.2.post1, <= 0.6.2.post1 or >= 0.6.3, <= 0.6.3 or >= 0.6.4, <= 0.6.4 or >= 0.6.5, <= 0.6.5 or >= 0.7.0, <= 0.7.0 or >= 0.7.0.post1, <= 0.7.0.post1 or >= 0.7.0.post2, <= 0.7.0.post2 or >= 0.7.0.post3, <= 0.7.0.post3 or >= 0.7.1, <= 0.7.1 or <= 0.12.2 or >= 0.0.10, <= 0.0.10 or >= 0.0.11, <= 0.0.11 or >= 0.0.12, <= 0.0.12 or >= 0.0.13, <= 0.0.13 or >= 0.0.14, <= 0.0.14 or >= 0.1.0, <= 0.1.0 or >= 0.10.0, <= 0.10.0 or >= 0.10.1, <= 0.10.1 or >= 0.10.2, <= 0.10.2 or >= 0.11.0, <= 0.11.0 or >= 0.11.1, <= 0.11.1 or >= 0.12.0, <= 0.12.0 or >= 0.12.1, <= 0.12.1 or >= 0.12.2, <= 0.12.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.2.5, <= 0.2.5 or >= 0.2.6, <= 0.2.6 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.5.0, <= 0.5.0 or >= 0.5.1, <= 0.5.1 or >= 0.5.2, <= 0.5.2 or >= 0.5.2.post1, <= 0.5.2.post1 or >= 0.5.3, <= 0.5.3 or >= 0.6.0, <= 0.6.0 or >= 0.6.0a0, <= 0.6.0a0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.2.post1, <= 0.6.2.post1 or >= 0.6.3, <= 0.6.3 or >= 0.6.4, <= 0.6.4 or >= 0.6.5, <= 0.6.5 or >= 0.7.0, <= 0.7.0 or >= 0.7.0.post1, <= 0.7.0.post1 or >= 0.7.0.post2, <= 0.7.0.post2 or >= 0.7.0.post3, <= 0.7.0.post3 or >= 0.7.1, <= 0.7.1 or >= 0.7.2, <= 0.7.2 or >= 0.7.2.post1, <= 0.7.2.post1 or >= 0.7.3, <= 0.7.3 or >= 0.8.0, <= 0.8.0 or >= 0.9.0, <= 0.9.0 or >= 0.9.1, <= 0.9.1 or >= 0.9.2, <= 0.9.2 or >= 0.9.2.post1, <= 0.9.2.post1 or <= 0.12.3 or >= 0.0.10, <= 0.0.10 or >= 0.0.11, <= 0.0.11 or >= 0.0.12, <= 0.0.12 or >= 0.0.13, <= 0.0.13 or >= 0.0.14, <= 0.0.14 or >= 0.1.0, <= 0.1.0 or >= 0.10.0, <= 0.10.0 or >= 0.10.1, <= 0.10.1 or >= 0.10.2, <= 0.10.2 or >= 0.11.0, <= 0.11.0 or >= 0.11.1, <= 0.11.1 or >= 0.12.0, <= 0.12.0 or >= 0.12.1, <= 0.12.1 or >= 0.12.2, <= 0.12.2 or >= 0.12.3, <= 0.12.3 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.2.5, <= 0.2.5 or >= 0.2.6, <= 0.2.6 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.5.0, <= 0.5.0 or >= 0.5.1, <= 0.5.1 or >= 0.5.2, <= 0.5.2 or >= 0.5.2.post1, <= 0.5.2.post1 or >= 0.5.3, <= 0.5.3 or >= 0.6.0, <= 0.6.0 or >= 0.6.0a0, <= 0.6.0a0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.2.post1, <= 0.6.2.post1 or >= 0.6.3, <= 0.6.3 or >= 0.6.4, <= 0.6.4 or >= 0.6.5, <= 0.6.5 or >= 0.7.0, <= 0.7.0 or >= 0.7.0.post1, <= 0.7.0.post1 or >= 0.7.0.post2, <= 0.7.0.post2 or >= 0.7.0.post3, <= 0.7.0.post3 or >= 0.7.1, <= 0.7.1 or >= 0.7.2, <= 0.7.2 or >= 0.7.2.post1, <= 0.7.2.post1 or >= 0.7.3, <= 0.7.3 or >= 0.8.0, <= 0.8.0 or >= 0.9.0, <= 0.9.0 or >= 0.9.1, <= 0.9.1 or >= 0.9.2, <= 0.9.2 or >= 0.9.2.post1, <= 0.9.2.post1 or < 0.13.0 or >= 0.0.10, <= 0.0.10 or >= 0.0.11, <= 0.0.11 or >= 0.0.12, <= 0.0.12 or >= 0.0.13, <= 0.0.13 or >= 0.0.14, <= 0.0.14 or >= 0.1.0, <= 0.1.0 or >= 0.10.0, <= 0.10.0 or >= 0.10.1, <= 0.10.1 or >= 0.10.2, <= 0.10.2 or >= 0.11.0, <= 0.11.0 or >= 0.11.1, <= 0.11.1 or >= 0.12.0, <= 0.12.0 or >= 0.12.1, <= 0.12.1 or >= 0.12.2, <= 0.12.2 or >= 0.12.3, <= 0.12.3 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.2.5, <= 0.2.5 or >= 0.2.6, <= 0.2.6 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.5.0, <= 0.5.0 or >= 0.5.1, <= 0.5.1 or >= 0.5.2, <= 0.5.2 or >= 0.5.2.post1, <= 0.5.2.post1 or >= 0.5.3, <= 0.5.3 or >= 0.6.0, <= 0.6.0 or >= 0.6.0a0, <= 0.6.0a0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.2.post1, <= 0.6.2.post1 or >= 0.6.3, <= 0.6.3 or >= 0.6.4, <= 0.6.4 or >= 0.6.5, <= 0.6.5 or >= 0.7.0, <= 0.7.0 or >= 0.7.0.post1, <= 0.7.0.post1 or >= 0.7.0.post2, <= 0.7.0.post2 or >= 0.7.0.post3, <= 0.7.0.post3 or >= 0.7.1, <= 0.7.1 or >= 0.7.2, <= 0.7.2 or >= 0.7.2.post1, <= 0.7.2.post1 or >= 0.7.3, <= 0.7.3 or >= 0.8.0, <= 0.8.0 or >= 0.9.0, <= 0.9.0 or >= 0.9.1, <= 0.9.1 or >= 0.9.2, <= 0.9.2 or >= 0.9.2.post1, <= 0.9.2.post1
- Patched version
- Not yet available
An early warning has been issued for a critical vulnerability in the lmdeploy package that could allow remote code execution. Users of affected versions should take immediate action.
What happened
The lmdeploy package, when configured for disaggregated serving, deserializes peer messages using pickle. This process does not adequately verify the source of the messages, allowing a remote attacker to execute arbitrary code in the engine process. The vulnerability, tracked as CVE-2026-76850, has a CVSS score of 9.8, indicating a critical severity. It is not yet confirmed to be exploited in the wild.
Affected versions of lmdeploy include a wide range of releases, from 0.0.10 to 0.12.3 and beyond. The vulnerability exists in versions that enable disaggregated serving. Users are advised to consult the primary sources for the exact version ranges affected.
What to do about it
- Disable disaggregated serving in lmdeploy to mitigate the risk of remote code execution.
- Review your lmdeploy configuration to ensure that disaggregated serving is not enabled.
- Monitor the primary sources for updates on a potential patch or fix for this vulnerability.
- Consider alternative serving configurations that do not expose the same level of risk.
- Stay informed about the status of this vulnerability by checking the provided sources regularly.
How 0Day would have caught this
lmdeploy is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using lmdeploy with disaggregated serving enabled and your version falls within the affected range, you are potentially at risk.
What should I do right now?
Immediately disable disaggregated serving in lmdeploy and monitor the situation for updates on a patch.
Is there a patch available?
No official fix has been published yet. Continue to monitor the sources for updates.