High · CVSS 7.5 April 22, 2026 · LMDeploy Security Advisory

LMDeploy Vision-Language SSRF

Unvalidated Image URL Fetching Exposes Cloud Metadata and Internal Services

CVE-2026-33626 affects LMDeploy's image-loading functionality for vision-language models. When processing OpenAI-compatible chat requests with image_url parameters, the server fetches URLs without validating destination hosts — creating a Server-Side Request Forgery primitive that grants access to cloud metadata services, internal databases, and private network topology. The vulnerability was exploited in the wild within 12 hours and 31 minutes of advisory publication.

1 CVE
7.5 CVSS Score
12h 31m Time to Exploit
Patched Status

"Attackers are increasingly weaponizing vulnerabilities in inference servers, model gateways, and agent orchestration tools within hours of advisory publication."

Vulnerability

CVE-2026-33626 High · 7.5 SSRF

Vision-Language Image Loader SSRF

LMDeploy's vision-language model handler processes image_url parameters from OpenAI-compatible chat requests by fetching the referenced URL server-side. No validation of destination hosts is performed, allowing an attacker to supply internal addresses — including cloud metadata endpoints, localhost services, and private network hosts — as the image source. The server then acts as an unwitting proxy, returning the fetched content to the attacker.

Affected: LMDeploy < 0.7.3  ·  Fixed: 0.7.3
Impact: Server-side request forgery enabling cloud credential theft via metadata services, internal service enumeration, and private network topology discovery.

Attack Path

1

Craft Malicious Image Request

Attacker submits an OpenAI-compatible chat completion request with an image_url value pointing to an internal target — such as http://169.254.169.254/latest/meta-data/.

Any user with API access to the LMDeploy instance can trigger this — no elevated privileges required.

2

Server Fetches Internal URL

LMDeploy fetches the supplied URL server-side without host validation. The request originates from the model-serving host — inside the network perimeter, trusted by internal services.

The server has access to resources the attacker cannot reach directly. This is what makes SSRF on inference servers particularly dangerous in cloud environments.

3

Cloud Metadata / Internal Service Access

The server response — AWS IAM credentials, Redis data, MySQL responses, admin endpoint content — is returned to the attacker via the API response.

AWS metadata at 169.254.169.254 returns short-lived IAM credentials that can be used immediately for cloud-level privilege escalation.

4

Network Enumeration and Lateral Movement

By probing ranges of internal addresses and ports, attacker maps private network topology — discovering services, admin interfaces, and additional attack surfaces invisible from the public internet.

SSRF-based enumeration is silent from a perimeter perspective. Internal firewall rules do not apply to requests originating from within the network.

Impact

Cloud Credentials

  • AWS IAM role credentials
  • Instance identity documents
  • Security group metadata
  • Short-lived access tokens

Internal Services

  • Redis cache contents
  • MySQL query access
  • Admin API endpoints
  • Localhost-only interfaces

Network Intelligence

  • Private network topology
  • Internal service discovery
  • Port and service enumeration
  • Additional attack surface mapping

Speed of exploitation: This CVE was weaponized within 12 hours and 31 minutes of the advisory going public. AI inference servers and model gateways are now first-class targets — patch windows measured in hours, not days.

Response Checklist

STEP 01 Upgrade LMDeploy to 0.7.3+ Immediate

Apply the patch across all environments — production, staging, and development. Given the 12-hour exploitation window observed in the wild, treat this as a same-day upgrade regardless of environment classification.

STEP 02 Audit Access Logs for Suspicious image_url References Immediate

Search API request logs for image_url values containing internal IP ranges, link-local addresses (169.254.x.x), localhost, or private RFC-1918 ranges. Any hits indicate active exploitation attempts.

  • 169.254.169.254 — AWS/GCP/Azure metadata service
  • 10.x.x.x / 172.16–31.x.x / 192.168.x.x — RFC-1918 private ranges
  • 127.0.0.1 / localhost — loopback interface
  • 0.0.0.0 — wildcard address, often used in SSRF bypass attempts
STEP 03 Block Metadata Service Access from Model-Serving Workloads Immediate

Apply network-level controls preventing model-serving processes from reaching cloud metadata endpoints. On AWS, use IMDSv2 and restrict outbound access at the security group or NACLs level.

  • Block egress to 169.254.169.254 from inference workloads
  • Enforce IMDSv2 (token-required) on all AWS instances running LMDeploy
  • Apply outbound firewall rules restricting RFC-1918 access from model servers
STEP 04 Rotate Cloud Credentials if Exploitation is Suspected Urgent

If log review reveals suspicious image_url activity before the patch was applied, assume IAM credentials reachable from the instance may be compromised. Rotate all instance-associated roles and review CloudTrail for unusual API calls.

STEP 05 Treat AI Inference Servers as Security-Critical Infrastructure Important

Inference servers, model gateways, and agent orchestration tools have the same network access as any other server — and are now actively targeted. Apply the same patching cadence, access controls, and monitoring you apply to web-facing production services.

References

[1] NVD

CVE-2026-33626 — LMDeploy Vision-Language Image Loader SSRF

[2] LMDeploy Security Advisory

LMDeploy v0.7.3 release notes — SSRF fix in vision-language image URL handling, April 22, 2026

Source: LMDeploy security advisory, CVE-2026-33626, April 22, 2026. This advisory is an independent defensive guide produced by Spectreworks AI for educational purposes only.