logo

Attackers Exploit LMDeploy Flaw in the Wild Within 12 Hours of Advisory

ID: ec1485f4-d18c-51c3-9622-54b3be33b069

STIX ID: report--ec1485f4-d18c-51c3-9622-54b3be33b069

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Divya

...
...

A high-severity Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-33626, CVSS 7.5) in LMDeploy's load_image() was exploited roughly 12.5 hours after public disclosure; an attacker from 103.116.72.119 performed rapid probes including AWS metadata access (169.254.169.254), Redis and MySQL port checks on localhost, and used an OOB DNS callback (cw2mhnbd.requestrepo.com) to confirm exploitation. The report includes the root cause, attack phases, IOCs, and recommends upgrading to LMDeploy v0.12.3+, adding reverse proxies, and applying strict egress controls for AI inference hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.