CVE-2026-103040
9.8 CRITICALpublic exploit availablePublished 2026-09-29 · Updated 2026-09-29
AI risk analysis
- Summary
- LightLLM versions through 1.2.0 are vulnerable to remote code execution due to an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code via crafted serialized objects.
- Exploitability
- Exploitation is relatively straightforward given the unauthenticated nature and the presence of a RPyC server with deserialization enabled. Attackers must start the service with the --enable_profiling flag.
- Blast radius
- If exploited, this vulnerability could lead to complete compromise of the affected system, potentially allowing attackers to execute arbitrary code and gain full control over the system.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Disable the profiling feature by not starting the service with the --enable_profiling flag, or upgrade to a version later than 1.2.0 if available.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to the profiler command queue.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-502
Public exploit & PoC references
All references
- https://github.com/ModelTC/LightLLM
- https://github.com/ModelTC/LightLLM/issues/1597
- https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/profiler_service.py#L32-L34
- https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/profiler_service.py#L46-L50
- https://www.vulncheck.com/advisories/lightllm-through-1.2.0-unauthenticated-remote-code-execution-via-router-profiler-rpyc-service
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-103041PoC
- CRITICALCVE-2026-76723
- CRITICALCVE-2026-70416
- CRITICALCVE-2026-70554PoC
- CRITICALCVE-2026-81657
- CRITICALCVE-2026-82384PoC
- CRITICALCVE-2023-54400PoC
- CRITICALCVE-2026-100740
Related by shared AI tags and CWE weakness class. Browse the full archive.