CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-103041 — LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cac...

·Source: NIST NVD

Updated:

Executive Summary

LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges.

Analysis

LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges. CVSS Score: 9.8. Published: 2026-09-29T23:17:21.630.

Indicators of Compromise (1)

CVE (1)
CVE-2026-103041
Source Attribution

Originally published by NIST NVD on Sep 29, 2026. Verified by: NIST.

Related Threats