Attackers Exploit LMDeploy Flaw in the Wild Within 12 Hours of Advisory
ID: ec1485f4-d18c-51c3-9622-54b3be33b069
STIX ID: report--ec1485f4-d18c-51c3-9622-54b3be33b069
Feed Name: GBHackers
A high-severity Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-33626, CVSS 7.5) in LMDeploy's load_image() was exploited roughly 12.5 hours after public disclosure; an attacker from 103.116.72.119 performed rapid probes including AWS metadata access (169.254.169.254), Redis and MySQL port checks on localhost, and used an OOB DNS callback (cw2mhnbd.requestrepo.com) to confirm exploitation. The report includes the root cause, attack phases, IOCs, and recommends upgrading to LMDeploy v0.12.3+, adding reverse proxies, and applying strict egress controls for AI inference hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
