Junglewise Threat Intelligence

CVE-2025-67729: PYSEC-2026-1578 - lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

CVE-2025-67729 · Severity: low · CVSS 3.1 · Published 2026-07-07

Technologies: lmdeploy (PyPI). Vendors: PyPI.

Executive brief

lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

Affected products

  • PyPI lmdeploy

Related threats