CRITICALVulnerability
Verified
Global
NVD CRITICAL: CVE-2026-103041 — LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cac...
·Source: NIST NVD
Updated:
Executive Summary
LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges.
Analysis
LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges. CVSS Score: 9.8. Published: 2026-09-29T23:17:21.630.