CVE-2026-33625 | InternLM LMDeploy up to 0.12.2 Quantization Config config.py eval quant_dtype code injection

SecurityVulns

A vulnerability described as critical has been identified in InternLM LMDeploy up to 0.12.2. This issue affects the function eval of the file lmdeploy/pytorch/config.py of the component Quantization Config. The manipulation of the argument quant_dtype results in code injection.

This vulnerability is cataloged as CVE-2026-33625. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More