LMDeploy's vision-language image loader turns a public model server into a path to cloud credentials and internal services. The standard response is to patch the package, but that does not undo secrets already exposed through SSRF.
The flaw is CVE-2026-33626 in load_image() and affects LMDeploy 0.12.0 and earlier with vision-language support. The first exploitation attempt was seen within 12 hours and 31 minutes of disclosure, and the bug can reach cloud metadata services, internal networks, Redis, MySQL, and other private resources.
The speed matters because exposed LMDeploy installs can be probed and abused almost immediately after disclosure. That leaves a short window before attackers start using the server as a credential source and internal scanner.