LightLLM 1.2.0 及更早版本中,当使用 标志启动时,路由分析器服务(router profiler service)存在远程代码执行漏洞。该服务暴露了一个未经验证的 RPyC 服务器,并启用了 pickle 反序列化功能。攻击者可通过向分析命令队列发送特制的序列化对象,实现任意代码的执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103041 | 9.8 CRITICAL | LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Embed Cache RPyC Service |
| CVE-2026-103042 | 7.5 HIGH | LightLLM through 1.2.0 Unauthenticated Memory Exhaustion via NCCL Control Channel set_valu |
No comments yet