Medium severity5.3NVD Advisory· Published Apr 3, 2025· Updated Jun 17, 2026
CVE-2025-3162
CVE-2025-3162
Description
A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file lmdeploy/lmdeploy/vl/model/utils.py of the component PT File Handler. The manipulation leads to deserialization. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
lmdeployPyPI | <= 0.7.1 | — |
Affected products
3Patches
Vulnerability mechanics
References
7- github.com/InternLM/lmdeploy/issues/3255nvdExploitIssue TrackingVendor AdvisoryWEB
- github.com/InternLM/lmdeploy/issues/3255nvdExploitIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-7vc5-mjwp-c8fqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-3162ghsaADVISORY
- vuldb.comnvdThird Party AdvisoryVDB EntryWEB
- vuldb.comnvdThird Party AdvisoryVDB EntryWEB
- vuldb.comnvdPermissions RequiredVDB EntryWEB
News mentions
0No linked articles in our index yet.