Impact
The privilege‑elevating flaw stems from the LMdeploy RPC server's use of Python's pickle.loads without any sanitization, allowing an attacker to send crafted serialized data that is executed on the server. This vulnerability can enable full remote code execution on systems that expose the RPC service, compromising confidentiality, integrity, and availability of the entire deployment.
Affected Systems
InternLM lmdeploy, versions 0.9.1 up to and including 0.10.1 are affected, while version 0.10.2 and later contain the fix.
Risk and Exploitability
The CVSS score of 9.8 marks it as critical; the EPSS score of less than 1% indicates a low current exploitation probability, and it is not yet listed in the CISA KEV catalog. The attack vector is likely remote, via the RPC interface exposed by the service, and an attacker only needs the ability to send a crafted payload to the RPC endpoint to trigger the vulnerability.
OpenCVE Enrichment
Github GHSA