CVE-2026-103040 PUBLISHED

LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Router Profiler RPyC Service

Assigner: VulnCheck
Reserved: 29.09.2026 Published: 29.09.2026 Updated: 30.09.2026

LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to the profiler command queue.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor ModelTC
Product LightLLM
Versions Default: unaffected
  • affected from 0 to 1.2.0 (incl.)

Credits

  • Mingkai Yu finder
  • Jiapeng Li finder
  • Jiajia Liu finder

References

Problem Types

  • Deserialization of Untrusted Data CWE