CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-103040 — LightLLM through 1.2.0 contains a remote code execution vulnerability in the rou...

·Source: NIST NVD

Updated:

Executive Summary

LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to the profiler command queue.

Analysis

LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to the profiler command queue. CVSS Score: 9.8. Published: 2026-09-29T23:17:21.447.

Indicators of Compromise (1)

CVE (1)
CVE-2026-103040
Source Attribution

Originally published by NIST NVD on Sep 29, 2026. Verified by: NIST.

Related Threats