High
github
·
GHSA-3hmm-rh5q-gwwr
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
Published Sep 18, 2026
CVSS 8.8
Summary
lmdeploy
Affected AI Products
huggingface
pytorch