PT-2026-102935 · Lightllm · Lightllm
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LightLLM versions prior to 1.2.1
Description
The router profiler service contains a flaw that allows remote code execution when the application is started with the
--enable profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled. An attacker can execute arbitrary code by sending crafted serialized objects to the profiler command queue. Pickle deserialization is a process where a Python object is converted from a byte stream back into an object, which can be exploited to run malicious commands if the input is not trusted.Recommendations
Update to version 1.2.1 or later.
As a temporary mitigation, avoid starting the service with the
--enable profiling flag.Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lightllm