Attackers began exploiting CVE-2026-33626 in LMDeploy less than 13 hours after public disclosure, using a server-side request forgery flaw in vision-language request handling to make inference servers fetch attacker-controlled and internal URLs. Sysdig said the bug affects LMDeploy 0.12.0 and earlier with vision-language support, where image_url input is not properly restricted, and observed an eight-minute attack against its honeypot that probed AWS instance metadata, localhost services, an unauthenticated administrative endpoint, and an out-of-band callback domain. The activity included scans of loopback ports associated with Redis, MySQL, and HTTP services, underscoring the risk of exposing AI inference infrastructure to internal network discovery and cloud credential theft.
The disclosures also highlighted broader weaknesses in LLM-serving platforms. LiteLLM published three advisories for LiteLLM Proxy that researchers said can be chained to achieve remote code execution, including an unauthenticated SQL injection (GHSA-r75f-5x8p-qvmc), a server-side template injection flaw, and an authenticated command-execution issue in MCP stdio test endpoints. The affected LiteLLM range is 1.81.16 through 1.83.6, with fixes available in 1.83.7-stable and later, while LMDeploy users were urged to upgrade to v0.12.3+, enforce IMDSv2, restrict egress, rotate IAM credentials, and monitor inference hosts for requests to metadata, loopback, and private-network addresses.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Users were advised to upgrade LiteLLM Proxy to version 1.83.7-stable or later to address the newly disclosed vulnerabilities. The disclosure noted that official container images run the proxy as root, which can increase impact on vulnerable hosts.
LiteLLM disclosed three GitHub Security Advisories covering an unauthenticated SQL injection, a server-side template injection, and an authenticated command-execution flaw in LiteLLM Proxy. The vulnerabilities affect versions 1.81.16 through 1.83.6 and can be chained to achieve remote code execution.
Following disclosure and observed exploitation, defenders were advised to remediate by upgrading LMDeploy to v0.12.3 or newer and to harden deployments with measures such as IMDSv2 enforcement, egress restrictions, credential rotation, and monitoring for suspicious internal URL access.
On April 22, 2026, Sysdig observed an attacker exploit the LMDeploy SSRF vulnerability against its honeypot about 12.5 hours after the advisory became public. The attacker probed AWS metadata, localhost services, an unauthenticated administrative endpoint, and an out-of-band callback domain during an eight-minute session.
GitHub published a security advisory on an SSRF flaw in LMDeploy affecting vision-language request handling, later tracked as CVE-2026-33626. The issue allows user-supplied image_url values to trigger requests to arbitrary internal or external URLs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcereddit.com
Open sourcerunzero.com
Open sourcewebflow.sysdig.com
Open sourcesysdig.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.