As outlined in The Hacker News, a critical security flaw in LMDeploy, an open-source toolkit for managing large language models (LLMs), is being actively exploited in the wild. This vulnerability, identified as CVE-2026-33626, allows for server-side request forgery (SSRF) and poses a significant risk to systems utilizing the toolkit.The SSRF vulnerability resides within LMDeploy's vision-language module, specifically in the load_image() function, which fails to validate internal or private IP addresses when fetching URLs. This allows attackers to access sensitive cloud metadata services, internal networks, and other resources.Researchers at Sysdig detected exploitation attempts within 13 hours of the vulnerability's public disclosure, observing attackers using the flaw to port scan internal networks, target AWS Instance Metadata Service (IMDS) and Redis instances, and perform out-of-band DNS exfiltration. The exploitation involved multiple requests across different vision-language models to evade detection.Source: The Hacker News
AI/ML, Vulnerability Management, Patch/Configuration Management
LMDeploy vulnerability exploited, highlighting AI infrastructure risks

An In-Depth Guide to AI
Get essential knowledge and practical strategies to use AI to better your security program.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



