Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
rapid-weaponizationai-platform-securitycloud-service-vulnerabilityproof-of-concept-release

LMDeploy SSRF Was Exploited Within Hours as LiteLLM Proxy Disclosed RCE Chain

Updated 2mo agoFirst seen Apr 22, 20265 sources

Attackers began exploiting CVE-2026-33626 in LMDeploy less than 13 hours after public disclosure, using a server-side request forgery flaw in vision-language request handling to make inference servers fetch attacker-controlled and internal URLs. Sysdig said the bug affects LMDeploy 0.12.0 and earlier with vision-language support, where image_url input is not properly restricted, and observed an eight-minute attack against its honeypot that probed AWS instance metadata, localhost services, an unauthenticated administrative endpoint, and an out-of-band callback domain. The activity included scans of loopback ports associated with Redis, MySQL, and HTTP services, underscoring the risk of exposing AI inference infrastructure to internal network discovery and cloud credential theft.

The disclosures also highlighted broader weaknesses in LLM-serving platforms. LiteLLM published three advisories for LiteLLM Proxy that researchers said can be chained to achieve remote code execution, including an unauthenticated SQL injection (GHSA-r75f-5x8p-qvmc), a server-side template injection flaw, and an authenticated command-execution issue in MCP stdio test endpoints. The affected LiteLLM range is 1.81.16 through 1.83.6, with fixes available in 1.83.7-stable and later, while LMDeploy users were urged to upgrade to v0.12.3+, enforce IMDSv2, restrict egress, rotate IAM credentials, and monitor inference hosts for requests to metadata, loopback, and private-network addresses.

Share:
LMDeploy SSRF Was Exploited Within Hours as LiteLLM Proxy Disclosed RCE Chain
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Apr 23, 20262mo ago

LiteLLM releases fixed version 1.83.7-stable

Users were advised to upgrade LiteLLM Proxy to version 1.83.7-stable or later to address the newly disclosed vulnerabilities. The disclosure noted that official container images run the proxy as root, which can increase impact on vulnerable hosts.

LiteLLM discloses three proxy flaws enabling RCE chains

LiteLLM disclosed three GitHub Security Advisories covering an unauthenticated SQL injection, a server-side template injection, and an authenticated command-execution flaw in LiteLLM Proxy. The vulnerabilities affect versions 1.81.16 through 1.83.6 and can be chained to achieve remote code execution.

Apr 22, 20262mo ago

LMDeploy users advised to upgrade to version 0.12.3 or later

Following disclosure and observed exploitation, defenders were advised to remediate by upgrading LMDeploy to v0.12.3 or newer and to harden deployments with measures such as IMDSv2 enforcement, egress restrictions, credential rotation, and monitoring for suspicious internal URL access.

Attackers exploit LMDeploy flaw against Sysdig honeypot within hours

On April 22, 2026, Sysdig observed an attacker exploit the LMDeploy SSRF vulnerability against its honeypot about 12.5 hours after the advisory became public. The attacker probed AWS metadata, localhost services, an unauthenticated administrative endpoint, and an out-of-band callback domain during an eight-minute session.

Apr 21, 20262mo ago

GitHub publishes LMDeploy SSRF advisory GHSA-6w67-hwm5-92mq

GitHub published a security advisory on an SSRF flaw in LMDeploy affecting vision-language request handling, later tracked as CVE-2026-33626. The issue allows user-supplied image_url values to trigger requests to arbitrary internal or external URLs.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

13 LINKEDOpen in app
Affected products
6 linked
OllamaVllmText Generation InferenceInteractshRedisMysql
Organizations
6 linked
Amazon Web ServicesGitHubSysdigShanghai AI LaboratoryPrime Security Corp.Microsoft Corporation
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

LMDeploy SSRF Was Exploited Within Hours as LiteLLM Proxy Disclosed RCE Chain | Mallory