CVE-2026-103040
LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to the profiler command queue.
- Published Sep 29, 2026
- CVSS 9.3 critical
- 0.8% chance of exploitation in the next 30 days (EPSS)