CVE-2026-46432
📛 CVE Title
(no title)
Description
LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- high
- CVSS score
- 7.8 / 10
- CVSS vector
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Effective score
- 7.8 / 10 HIGH source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2026-46432
- Linked Threat
- CVE-2026-46432 — CVE-2026-46432
NVD / KEV / EPSS data refreshed 2026-05-25 00:15 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-35873 - Assigner
- GitHub_M
- Published
- Jun 9, 2026, 11:05:38 PM
- Updated
- Jun 11, 2026, 3:55:31 AM
- EUVD base score (CVSS 3.1)
-
7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EUVD-reported EPSS
- 0.1400
- Vendors
- InternLM
- Products
-
LMDeploy (≤ 0.12.3)
- Aliases
-
GHSA-m549-qq94-fvhg
ENISA description: LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDeploy is vulnerable to arbitrary code execution through hardcoded "trust_remote_code=True" in multiple HuggingFace model-loading call sites. At time of publication, there are no publicly available patches.
EUVD references (1)
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (2)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://nvd.nist.gov/vuln/detail/CVE-2026-46432 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-46432 tenable:www.cve.org
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:advisories.gitlab.com
Detect and mitigate CVE-2026-46432 with GitLab Dependency Scanning Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities.
2026-05-26 03:00 UTC -
web:blackswan-cybersecurity.com
Cloud Files API activity originating outside legitimate OneDrive/sync processes. Mitigation Steps: Apply all Windows updates immediately (monitor MSRC for an emergency RedSun-specific patch . None released as of April 17, 2026 ). Supplement Defender with a secondary EDR solution (e.g., Huntress) capable of detecting Defender bypasses.
2026-05-26 03:00 UTC -
web:blog.qualys.com
Oracle released its second quarterly edition of this year's Critical Patch Update. The update received patches for 481 security vulnerabilities.
2026-05-26 03:00 UTC -
web:blogs.oracle.com
For more information about the Critical Patch Update program, see the security vulnerability remediation practices page located on the Oracle Trust Center.
2026-05-26 03:00 UTC -
web:github.com
Because the model path is supplied by the operator or deployment configuration, an attacker who can control the model_path used by an lmdeploy serving process can point it to an attacker-controlled HuggingFace model repository. When lmdeploy starts and initializes the model, Transformers may download and execute remote Python code from that repository.
2026-05-26 03:00 UTC -
web:guide.sonatype.com
Technical security analysis for CVE-2026-46432 . CVSS 7.8 severity. View CVSS vectors, CWE classifications, and exploit maturity ratings.
2026-05-26 03:00 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-26 03:00 UTC -
web:vulert.com
Learn about CVE-2026-46432 , a critical vulnerability in lmdeploy that allows arbitrary code execution. Update to version 0.13.0 to mitigate risks.
2026-05-26 03:00 UTC -
web:www.tenable.com
Oracle addresses 241 CVEs in its April Critical Patch Update, the second quarterly update of 2026 with 481 patches, including 34 critical updates.
2026-05-26 03:00 UTC -
web:www.windowslatest.com
Windows 11 April 2026 update adds Narrator Copilot support, faster Settings, File Explorer fixes, and key security improvements.
2026-05-26 03:00 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.