MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 22 h ago, last 22 h ago, peak #2

Critical LightLLM flaw exposes AI servers to remote code execution

Original: 🚨 CVE-2026-103041 — CVSS 9.3 CRITICAL LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache

A critical vulnerability, CVE-2026-103041, has been disclosed affecting LightLLM through version 1.2.0. In multimodal deployments, the software exposes an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Security researchers warn attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code remotely. With a CVSS score of 9.3, admins running LightLLM are being urged to review exposed services and update as soon as possible.

Why now: A newly disclosed critical vulnerability with a maximum-tier CVSS score and easy remote exploitation is being circulated among security professionals.

LightLLMRPyCCVE-2026-103041

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/420576