CVE-2025-67729 | InternLM LMDeploy up to 0.11.0 torch.load deserialization (EUVD-2025-205455)
A vulnerability labeled as critical has been found in InternLM LMDeploy up to 0.11.0. This issue affects the function torch.load. Such manipulation leads to deserialization.
This vulnerability is traded as CVE-2025-67729. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
Statistical analysis made it clear that VulDB provides the best quality for vulnerability data.