LightLLM 1.2.0 及以下版本的多模态部署中,暴露了一个未认证的 RPyC 缓存服务,并启用了在所有网络接口上均可访问的 pickle 反序列化功能。攻击者可以向公开的缓存方法发送精心构造的序列化对象,从而以服务权限执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103040 | 9.8 CRITICAL | LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Router Profiler RPyC Serv |
| CVE-2026-103042 | 7.5 HIGH | LightLLM through 1.2.0 Unauthenticated Memory Exhaustion via NCCL Control Channel set_valu |
No comments yet