> π Reframing (2026-05-02): implicit unsafe remote-code path, not "supply-chain" > > The accurate description of this vulnerability is: > "get_model_arch and related helpers hardcode trust_remote_code=True > with no opβ¦
| CVE ID | CVE-2026-46517 |
| Vendor | pip |
| Affected Product | lmdeploy |
| Vulnerability Type | Vulnerability |
| CVSS Score | 7.8 (HIGH) |
| Actively Exploited | β No known exploitation |
| Patch Status | See Vendor Advisory β |
| Reported By | CYBERDUDEBIVASH SENTINEL APEX Intelligence (via github_advisories) |
>
> > The accurate description of this vulnerability is: > "get_model_arch and related helpers hardcode trust_remote_code=True > with no opt-out, creating an implicit unsafe remote-code load path > on every model fetch." > > What this report does NOT claim: > * It is NOT a network-attack RCE β the user supplies the model > reference; LMDeploy honors it. > * It is NOT a "supply chain" CVE in the classical sense (where a > benign upstream is compromised) β the user explicitly types the > repo name. > > What this report DOES claim: > * Other inference frameworks (vLLM, TGI, Hugging Face transformers > itself) all expose --trust-remote-code as opt-in so that > users who consciously load known-safe
Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle β deployable in 5 minutes.