CVE-2026-103041: LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Embed Cache RPyC Service
LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
LightLLM multimodal deployments through version 1.2.0 are exposed when the embed cache RPyC service is reachable, because it listens on all network interfaces and permits unauthenticated access.
What does an attacker need to exploit this issue?
An attacker needs network access to the exposed RPyC cache service. No authentication, privileges, or user interaction are required; the attacker can submit a crafted serialized object to a cache method.
What level of access could exploitation provide?
Successful exploitation can execute arbitrary code with the privileges of the LightLLM service process. This can affect confidentiality, integrity, and availability.
What can be done if an update is not immediately available?
Restrict network access to the embed cache RPyC service so untrusted systems cannot reach it. Since the service is described as listening on all interfaces without authentication, network isolation is the available mitigation indicated by the affected exposure.