Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 30 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with __reduce__ methods to execute arbitrary code with service account privileges. | |
| Title | LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Visual-Only RPyC Service | |
| Weaknesses | CWE-502 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-30T19:38:06.768Z
Reserved: 2026-09-30T14:28:17.072Z
Link: CVE-2026-103395
Updated: 2026-09-30T19:37:52.709Z
Status : Deferred
Published: 2026-09-30T15:22:27.710
Modified: 2026-09-30T20:17:30.840
Link: CVE-2026-103395
No data.
OpenCVE Enrichment
Updated: 2026-09-30T17:45:05Z
-
CWE-502
Deserialization of Untrusted Data