A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerability is the function Open of the file lmdeploy/docs/en/conf.py. The manipulation leads to code injection. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
{ "nvd_published_at": "2025-04-03T16:15:37Z", "cwe_ids": [ "CWE-74", "CWE-94" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-04-23T19:37:39Z" }