Impact
lmdeploy contains a server‑side request forgery flaw that allows an attacker to specify an image_url in a chat completions request that redirects to internal or private IP addresses. The redirect is followed without re‑checking the safety guard, letting the server fetch data from internal services or metadata endpoints and return it to the attacker.
Affected Systems
InternLM’s lmdeploy product. All releases up to and including 0.14.0 are affected.
Risk and Exploitability
The CVSS score of 7.7 classifies this as high severity. The EPSS score of less than 1 % indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. Attackers would need to send a POST request to the chat completions endpoint with a crafted image_url that triggers an HTTP 302 redirect to a private IP or metadata service. The vulnerability is exploitable remotely from the Internet to internal targets.
OpenCVE Enrichment