LMDeploy SSRF Was Exploited Within Hours as LiteLLM Proxy Disclosed RCE Chain
Attackers began exploiting CVE-2026-33626 in LMDeploy less than 13 hours after public disclosure, using a server-side request forgery flaw in vision-language request handling to make inference servers fetch attacker-controlled and internal URLs. Sysdig said the bug affects LMDeploy 0.12.0 and earlier with vision-language support, where image_url input is not properly restricted, and observed an eight-minute attack against its honeypot that probed AWS instance metadata, localhost services, an unauthenticated administrative endpoint, and an out-of-band callback domain. The activity included scans of loopback ports associated with Redis, MySQL, and HTTP services, underscoring the risk of exposing AI inference infrastructure to internal network discovery and cloud credential theft.
The disclosures also highlighted broader weaknesses in LLM-serving platforms. LiteLLM published three advisories for LiteLLM Proxy that researchers said can be chained to achieve remote code execution, including an unauthenticated SQL injection (GHSA-r75f-5x8p-qvmc), a server-side template injection flaw, and an authenticated command-execution issue in MCP stdio test endpoints. The affected LiteLLM range is 1.81.16 through 1.83.6, with fixes available in 1.83.7-stable and later, while LMDeploy users were urged to upgrade to v0.12.3+, enforce IMDSv2, restrict egress, rotate IAM credentials, and monitor inference hosts for requests to metadata, loopback, and private-network addresses.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
5 events from the most recent confirmed update back to the earliest known activity.
LiteLLM releases fixed version 1.83.7-stable
Users were advised to upgrade LiteLLM Proxy to version 1.83.7-stable or later to address the newly disclosed vulnerabilities. The disclosure noted that official container images run the proxy as root, which can increase impact on vulnerable hosts.
LiteLLM discloses three proxy flaws enabling RCE chains
LiteLLM disclosed three GitHub Security Advisories covering an unauthenticated SQL injection, a server-side template injection, and an authenticated command-execution flaw in LiteLLM Proxy. The vulnerabilities affect versions 1.81.16 through 1.83.6 and can be chained to achieve remote code execution.
LMDeploy users advised to upgrade to version 0.12.3 or later
Following disclosure and observed exploitation, defenders were advised to remediate by upgrading LMDeploy to v0.12.3 or newer and to harden deployments with measures such as IMDSv2 enforcement, egress restrictions, credential rotation, and monitoring for suspicious internal URL access.
Attackers exploit LMDeploy flaw against Sysdig honeypot within hours
On April 22, 2026, Sysdig observed an attacker exploit the LMDeploy SSRF vulnerability against its honeypot about 12.5 hours after the advisory became public. The attacker probed AWS metadata, localhost services, an unauthenticated administrative endpoint, and an out-of-band callback domain during an eight-minute session.
GitHub publishes LMDeploy SSRF advisory GHSA-6w67-hwm5-92mq
GitHub published a security advisory on an SSRF flaw in LMDeploy affecting vision-language request handling, later tracked as CVE-2026-33626. The issue allows user-supplied image_url values to trigger requests to arbitrary internal or external URLs.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
5 references tracked. Mallory keeps watching after this page renders.
LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure
thehackernews.com
Open sourceExploit su LMDeploy CVE-2026-33626: attacco SSRF immediato dopo disclosure : r/netsec
reddit.com
Open sourceLiteLLM Proxy vulnerabilities: How to find impacted assets
runzero.com
Open sourceCVE-2026-33626: How attackers exploited LMDeploy LLM Inference Engines in 12 hours | Sysdig
webflow.sysdig.com
Open sourceCVE-2026-33626: How attackers exploited LMDeploy LLM Inference Engines in 12 hours | Sysdig
sysdig.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


