Mmastodon TechnologyCybersecurity first seen 11 h ago, last 11 h ago, peak #3
Critical RCE vulnerability disclosed in LightLLM
Original: 🚨 CVE-2026-103040 — CVSS 9.3 CRITICAL LightLLM through 1.2.0 contains a remote code execution vulnerability in the route
A critical remote code execution flaw, tracked as CVE-2026-103040 with a CVSS score of 9.3, has been disclosed in LightLLM through version 1.2.0. The vulnerability sits in the router profiler service when launched with the --enable_profiling flag, which exposes an unauthenticated RPyC server with pickle deserialization enabled, letting attackers run arbitrary code. Security teams are being urged to check whether their deployments are affected.
Why now: Security teams are alerting each other to a newly disclosed critical vulnerability that could expose AI serving infrastructure to takeover
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/420577