Mmastodon TechnologyCybersecurity first seen 20 h ago, last 20 h ago, peak #2
Critical LightLLM flaw exposes AI servers to remote code execution
Original: 🚨 CVE-2026-103041 — CVSS 9.3 CRITICAL LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache
A critical vulnerability, CVE-2026-103041, has been disclosed affecting LightLLM through version 1.2.0. In multimodal deployments, the software exposes an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Security researchers warn attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code remotely. With a CVSS score of 9.3, admins running LightLLM are being urged to review exposed services and update as soon as possible.
Why now: A newly disclosed critical vulnerability with a maximum-tier CVSS score and easy remote exploitation is being circulated among security professionals.
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/420576