Skip to content
archivevulnerability · 18 Sep 2026 · 17:14 UTC

GHSA-39wr-7q6h-cf68: LMDeploy has an SSRF bypass

HIGHHigh-risk vulnerability — CVSS 7.5

last 60 dispatches · spectrum

### Summary The URL checking logic in lmdeploy has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. ### Details The current lmdeploy project uses `_is_safe_url` to validate the input URL. The main logic is to perform security checks on the host portion of the URL extracted by urlparse to prevent SSRF attacks. However, there are indeed differences in parsing between urlparse and the library that actually sends the request. …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected