Executive Summary

A critical vulnerability, CVE-2026-103395, has been discovered in LightLLM through version 1.2.0. This vulnerability exposes an unauthenticated RPyC service with allow_pickle enabled, allowing attackers to execute arbitrary code with service account privileges. The vulnerability has a CVSS score of 9.8, indicating a high severity level.

Technical Analysis

The vulnerability class of CVE-2026-103395 is deserialization. The attack vector involves an unauthenticated attacker reaching the visual RPyC port and passing objects with __reduce__ methods to execute arbitrary code. The root cause is the enabled allow_pickle option in the RPyC service, which deserializes attacker-supplied arguments in the remote_infer_images method.

How It Gets Exploited

An unauthenticated remote attacker on the same network can reach the visual RPyC port and pass objects with __reduce__ methods to trigger the vulnerability. Specifically, the attacker sends a crafted object to the remote_infer_images method, which deserializes the object due to the allow_pickle setting. This deserialization process can lead to the execution of arbitrary code with the privileges of the service account. The attacker gains arbitrary code execution, potentially allowing them to pivot to internal systems or access sensitive data.

Impact Assessment

LightLLM versions up to 1.2.0 are affected by this vulnerability. An attacker can achieve arbitrary code execution, leading to potential confidentiality, integrity, and availability impacts. The CVSS score of 9.8 indicates a critical severity level.

Recommended Actions

Update LightLLM to version 1.2.1 or later. Block access to the RPyC service from untrusted networks. Implement network segmentation to limit the attack surface. Monitor for suspicious activity on the RPyC port and implement WAF rules to detect and prevent exploitation attempts.

Sources

  • National Vulnerability Database (NVD)
  • ModelTC/LightLLM GitHub repository
  • Vulncheck advisories