search
LightLLM
Trends
- 1Three unpatched critical flaws disclosed in LightLLMโผ๐จ LightLLM Mass Disclosure โ 3 CVEs, no patch CVE-2026-103040 (CVSS 9.8) โ unauthenticated RCE, router profiler RPyC CVE
Three vulnerabilities in LightLLM, an open-source large language model serving framework, have been disclosed without an available patch. The most serious, CVE-2026-103040, is rated 9.8 and allows unauthenticated remote code execution via the router profiler RPyC interface. A similar flaw, CVE-2026-103041, also rated 9.8, affects the embed cache RPyC service, while CVE-2026-103042, rated 7.5, enables memory exhaustion through the NCCL control channel. Security researchers are urging exposed deployments to restrict network access.
- 2Critical LightLLM flaw exposes AI servers to remote code executionโ๐จ CVE-2026-103041 โ CVSS 9.3 CRITICAL LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache
A critical vulnerability, CVE-2026-103041, has been disclosed affecting LightLLM through version 1.2.0. In multimodal deployments, the software exposes an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Security researchers warn attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code remotely. With a CVSS score of 9.3, admins running LightLLM are being urged to review exposed services and update as soon as possible.
- 3Critical RCE vulnerability disclosed in LightLLMโ๐จ CVE-2026-103040 โ CVSS 9.3 CRITICAL LightLLM through 1.2.0 contains a remote code execution vulnerability in the route
A critical remote code execution flaw, tracked as CVE-2026-103040 with a CVSS score of 9.3, has been disclosed in LightLLM through version 1.2.0. The vulnerability sits in the router profiler service when launched with the --enable_profiling flag, which exposes an unauthenticated RPyC server with pickle deserialization enabled, letting attackers run arbitrary code. Security teams are being urged to check whether their deployments are affected.
- 4New CVE Alert Issued for ModelTC LightLLMโCVE Alert: CVE-2026-103042 - ModelTC - LightLLM - https://www. redpacketsecurity.com/cve-aler t-cve-2026-103042-modeltc-
A security advisory has been published for CVE-2026-103042, a vulnerability affecting LightLLM, the large language model inference server developed by ModelTC. Threat intelligence accounts are circulating the alert to warn organisations running the software to review the flaw and check whether patches or mitigations are available.