CVE-2026-103395
CRITICALLightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with __reduce__ methods to execute arbitrary code with service account privileges.
Published: 9/30/2026Modified: 9/30/2026
References (6)
https://github.com/ModelTC/LightLLMhttps://github.com/ModelTC/LightLLM/issues/1610https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/visualserver/objs.py#L6-L11https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/visualserver/visual_only_manager.py#L138-L140https://www.vulncheck.com/advisories/lightllm-through-1.2.0-unauthenticated-remote-code-execution-via-visual-only-rpyc-servicehttps://github.com/ModelTC/LightLLM/issues/1610