PT-2026-102935 · Lightllm · Lightllm

·

CVE-2026-103040

·

Published

2026-09-29

·

Updated

2026-09-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LightLLM versions prior to 1.2.1
Description The router profiler service contains a flaw that allows remote code execution when the application is started with the --enable profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled. An attacker can execute arbitrary code by sending crafted serialized objects to the profiler command queue. Pickle deserialization is a process where a Python object is converted from a byte stream back into an object, which can be exploited to run malicious commands if the input is not trusted.
Recommendations Update to version 1.2.1 or later. As a temporary mitigation, avoid starting the service with the --enable profiling flag.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103040

Affected Products

Lightllm