OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-103040 (CVSS 9.3)

NVD · officialPublished Sep 29, 2026Risk 50/100

LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to the profiler command queue.

CVSS
9.3
AV:NetworkAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source