NVD CRITICAL: CVE-2026-103040 — LightLLM through 1.2.0 contains a remote code execution vulnerability in the rou...
LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to the profiler command queue.
CVE-2026-103040