Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9xq9-36w5-q796 | lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out |
Thu, 11 Jun 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Wed, 10 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Internlm
Internlm lmdeploy |
|
| Vendors & Products |
Internlm
Internlm lmdeploy |
Tue, 09 Jun 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardcoded "trust_remote_code=True" enables HF supply-chain RCE without user opt-in. At time of publication, there are no publicly available patches. | |
| Title | LMDeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out | |
| Weaknesses | CWE-1188 CWE-915 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-11T10:18:19.271Z
Reserved: 2026-05-14T19:12:32.755Z
Link: CVE-2026-46517
Updated: 2026-06-10T15:16:15.247Z
Status : Deferred
Published: 2026-06-10T00:16:53.827
Modified: 2026-06-11T12:16:31.507
Link: CVE-2026-46517
No data.
OpenCVE Enrichment
Updated: 2026-06-10T02:15:19Z
Github GHSA