PT-2026-103289 · Lightllm · Lightllm
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LightLLM versions prior to 1.2.1
Description
In
visual only deployments, an unauthenticated RPyC service is exposed with allow pickle enabled. This configuration allows the remote infer images() function to deserialize attacker-supplied arguments. An attacker can connect to the visual RPyC port and provide objects containing reduce methods to achieve remote code execution with service account privileges. RPyC is a transparent library for remote procedure calls, and pickle is a Python module used for serializing and deserializing objects.Recommendations
Update LightLLM to version 1.2.1 or later.
As a temporary mitigation, restrict network access to the visual RPyC port to prevent unauthenticated remote access.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lightllm