← Front PageAI Security Desk
AI Security
LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure
Critical LMDeploy LLM toolkit vulnerability exploited within 13 hours of disclosure, highlighting AI infrastructure risks.
Summary written by editorial AI · Source link below
CVSS7.5highCVE-2026-33626
A high-severity security flaw in LMDeploy, an open-source toolkit for compressing, deploying, and serving large language models (LLMs), has come under active exploitation in the wild less than 13 hours after its public disclosure. The vulnerability, tracked as CVE-2026-33626 (CVSS score: 7.5), relates to a Server-Side Request Forgery (SSRF) vulnerability that could be exploited to access
Continue at the source
Read the full report at THN (Feedburner)External link — opens at THN (Feedburner) in a new tab.
§
Continue with
More from the AI Security Desk
- Hugging Face warns an autonomous AI agent hacked its network20 Jul
- Jailbreak Foundry: From Papers to Runnable Attacks for Reproducible Benchmarking20 Jul
- Hidden in Thought: Transferable Chain-of-Thought Artifacts Induce Harmful Behavior20 Jul
- Poison to Detect: Detection of Targeted Overfitting in Federated Learning20 Jul
- Coercion and Deception in AI-to-AI Management: An Agentic Benchmark of Unprompted Escalation20 Jul