CVE-2026-103395: Unauthenticated RPyC Service Exposes LightLLM to Arbitrary Code Execution
A critical vulnerability in LightLLM through version 1.2.0 allows unauthenticated attackers to execute arbitrary code with service account privileges. The flaw is due to an exposed RPyC service with allow_pickle enabled, which deserializes attacker-supplied arguments. A CVSS score of 9.8 indicates the severity of this vulnerability.