PT-2026-103289 · Lightllm · Lightllm

·

CVE-2026-103395

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LightLLM versions prior to 1.2.1
Description In visual only deployments, an unauthenticated RPyC service is exposed with allow pickle enabled. This configuration allows the remote infer images() function to deserialize attacker-supplied arguments. An attacker can connect to the visual RPyC port and provide objects containing reduce methods to achieve remote code execution with service account privileges. RPyC is a transparent library for remote procedure calls, and pickle is a Python module used for serializing and deserializing objects.
Recommendations Update LightLLM to version 1.2.1 or later. As a temporary mitigation, restrict network access to the visual RPyC port to prevent unauthenticated remote access.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103395

Affected Products

Lightllm