{"id":"CVE-2025-3162","aliases":["GHSA-7vc5-mjwp-c8fq","PYSEC-2026-1577"],"url":"https://o3.security/vulnerability/CVE-2025-3162","summary":"InternLM LMDeploy PT File utils.py load_weight_ckpt deserialization","details":"A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file lmdeploy/lmdeploy/vl/model/utils.py of the component PT File Handler. The manipulation leads to deserialization. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.","published":"2025-04-03T15:00:18.405Z","modified":"2026-08-08T03:31:45.451744681Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"lmdeploy","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/3xxx/CVE-2025-3162.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3162"},{"type":"ADVISORY","url":"https://vuldb.com/?id.303108"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.542520"},{"type":"REPORT","url":"https://github.com/InternLM/lmdeploy/issues/3255"},{"type":"REPORT","url":"https://github.com/InternLM/lmdeploy/issues/3255#issue-2918985270"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.303108"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:31:45.451744681Z"}}