Critical SSRF Flaw in LMDeploy Exploited Within Hours of Disclosure – What You Need to Know

Quick Summary

A critical server-side request forgery (SSRF) vulnerability in LMDeploy (CVE-2026-33626) is being actively exploited less than 13 hours after its public disclosure. If you are using LMDeploy versions 0.12.0 or earlier with vision language support, patch immediately.

The Vulnerability

CVE-2026-33626 affects LMDeploy, an open-source toolkit for deploying large language models (LLMs). The SSRF flaw allows attackers to:

  • Access sensitive internal data
  • Steal cloud credentials from metadata endpoints
  • Port scan internal networks
  • Enable lateral movement within compromised environments

Why This Matters

The exploit window here is alarming. Attackers monitored the vulnerability disclosure and weaponized it in under half a day. This is not theoretical – active exploitation is confirmed in the wild.

Organizations running LLM infrastructure with vision language capabilities are at immediate risk. The attack vector typically involves crafting malicious requests that trick the server into accessing internal resources it should not expose.

Affected Versions

  • All LMDeploy versions 0.12.0 and prior with vision language support enabled
  • Self-hosted deployments are primary targets

Immediate Actions Required

  1. Upgrade to patched version – Check LMDeploy official repository for the latest release
  2. Audit network access – Review what internal endpoints your LLM servers can reach
  3. Monitor logs – Look for unusual outbound requests from your LLM infrastructure
  4. Restrict egress – Implement strict egress filtering for LLM deployment servers
  5. Rotate credentials – If exposure is suspected, rotate cloud credentials and API keys

The Bigger Picture

This incident highlights a growing trend: attackers are automating vulnerability exploitation faster than ever. The window between disclosure and active exploitation is shrinking from weeks to hours.

For teams running AI/ML infrastructure, this means:

  • Patch management cannot wait
  • Network segmentation around LLM servers is critical
  • Monitoring for SSRF patterns should be part of your security baseline

Bottom Line

If you are running LMDeploy in production, treat this as P0. The combination of active exploitation and the speed of weaponization makes this one of the most urgent AI infrastructure vulnerabilities of 2026.

Tzar C. Umang is a technology leader with over 15 years of experience making new technologies work for different industries. As the Chief Technology Officer at Makerspace Innovhub OPC and the Lead Developer for SUI Philippines, he leads projects that create growth and opportunities for everyone. With a strong background in blockchain development, AI engineering, and cybersecurity, Tzar has worked with organizations like the DOST Smarter Philippines Project Management Office and US startup Auto Genie. He is committed to helping the next generation of tech professionals, serving as a cybersecurity instructor at the University of Luzon and a mentor for the Saleng Mentors Group. In his free time, Tzar focuses on building practical solutions for education, healthcare, and new businesses.

Site Footer