MikeTrendsTrends right now

search

LightLLM

Trends

  1. 1
    Three unpatched critical flaws disclosed in LightLLMโ–ผ๐Ÿšจ LightLLM Mass Disclosure โ€” 3 CVEs, no patch CVE-2026-103040 (CVSS 9.8) โ€” unauthenticated RCE, router profiler RPyC CVEMmastodonTechnologyAI414 h ago

    Three vulnerabilities in LightLLM, an open-source large language model serving framework, have been disclosed without an available patch. The most serious, CVE-2026-103040, is rated 9.8 and allows unauthenticated remote code execution via the router profiler RPyC interface. A similar flaw, CVE-2026-103041, also rated 9.8, affects the embed cache RPyC service, while CVE-2026-103042, rated 7.5, enables memory exhaustion through the NCCL control channel. Security researchers are urging exposed deployments to restrict network access.

  2. 2
    Critical LightLLM flaw exposes AI servers to remote code executionโ—๐Ÿšจ CVE-2026-103041 โ€” CVSS 9.3 CRITICAL LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cacheMmastodonTechnologyCybersecurity018 h ago

    A critical vulnerability, CVE-2026-103041, has been disclosed affecting LightLLM through version 1.2.0. In multimodal deployments, the software exposes an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Security researchers warn attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code remotely. With a CVSS score of 9.3, admins running LightLLM are being urged to review exposed services and update as soon as possible.

  3. 3
    Critical RCE vulnerability disclosed in LightLLMโ—๐Ÿšจ CVE-2026-103040 โ€” CVSS 9.3 CRITICAL LightLLM through 1.2.0 contains a remote code execution vulnerability in the routeMmastodonTechnologyCybersecurity018 h ago

    A critical remote code execution flaw, tracked as CVE-2026-103040 with a CVSS score of 9.3, has been disclosed in LightLLM through version 1.2.0. The vulnerability sits in the router profiler service when launched with the --enable_profiling flag, which exposes an unauthenticated RPyC server with pickle deserialization enabled, letting attackers run arbitrary code. Security teams are being urged to check whether their deployments are affected.

  4. 4
    New CVE Alert Issued for ModelTC LightLLMโ—CVE Alert: CVE-2026-103042 - ModelTC - LightLLM - https://www. redpacketsecurity.com/cve-aler t-cve-2026-103042-modeltc-MmastodonTechnologyCybersecurity014 h ago

    A security advisory has been published for CVE-2026-103042, a vulnerability affecting LightLLM, the large language model inference server developed by ModelTC. Threat intelligence accounts are circulating the alert to warn organisations running the software to review the flaw and check whether patches or mitigations are available.