CVE-2026-103041 PUBLISHED

LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Embed Cache RPyC Service

Assigner: VulnCheck
Reserved: 29.09.2026 Published: 29.09.2026 Updated: 30.09.2026

LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor ModelTC
Product LightLLM
Versions Default: unaffected
  • affected from 0 to 1.2.0 (incl.)

Credits

  • Mingkai Yu finder
  • Jiapeng Li finder
  • Jiajia Liu finder

References

Problem Types

  • Deserialization of Untrusted Data CWE