Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-103040

CRITICAL NVD
CVSS Score 9.8
Severity CRITICAL
Published Sep 29, 2026
Vendor unknown

Description

LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to the profiler command queue.

References