Remote Code Execution in LightLLM Router Profiler Service by ModelTC
CVE-2026-103040
9.3CRITICAL
What is CVE-2026-103040?
LightLLM through version 1.2.0 features a vulnerability in its router profiler service when the service is initialized with the --enable_profiling flag. This scenario results in an unauthenticated RPyC server being exposed, with pickle deserialization activated. Attackers can exploit this flaw by sending specially crafted serialized objects to the profiler command queue, thereby executing arbitrary code on the server. It is crucial for users of LightLLM to review their configurations and consider upgrading to mitigate potential security risks.
Affected Version(s)
LightLLM 0 <= 1.2.0
