PT-2026-102936 · Lightllm · Lightllm

·

CVE-2026-103041

·

Published

2026-09-29

·

Updated

2026-09-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LightLLM versions prior to 1.2.1
Description Multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. This allows attackers to send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges. Pickle deserialization is a process where a Python object is converted from a byte stream back into an object, which can be exploited if the input is untrusted.
Recommendations Update LightLLM to version 1.2.1 or later.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103041

Affected Products

Lightllm