Act nowDisclosed

Advisory · CVE-2026-103041

Unauthenticated RCE in LightLLM via embed cache RPyC service

LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization on all interfaces, letting attackers send crafted serialized objects to execute arbitrary code.

Vendor
ModelTC
Product
LightLLM
Identifier / CWE
CVE-2026-103041
CWE-502
Action timing
Immediate
ELI5

Explain it like I’m five

LightLLM's multimodal cache works like a loading dock that accepts sealed packages from anyone and opens every one. An attacker drops off a package that turns into shell commands when the lid comes off.

SIMPLIFIED_ATTACK_PATH04 STEPS
  1. 01Multimodal deployment

    A LightLLM multimodal deployment starts the embed cache service, binding its RPyC interface on all network interfaces.

  2. 02Cache service exposed

    The cache service accepts unauthenticated connections and uses Python pickle deserialization on incoming objects.

  3. 03Crafted object sent

    A remote attacker sends a crafted serialized object to an exposed cache method.

  4. 04Payload executes

    Deserialization runs the attacker's code with the privileges of the LightLLM service.

What happened

LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers send crafted serialized objects to exposed cache methods, and deserialization executes arbitrary code with the privileges of the LightLLM service.

No patch release is documented in the disclosure at the time of writing; the advisory states only that LightLLM through 1.2.0 is affected.

What to do

  1. Inventory LightLLM multimodal deployments and confirm whether the embed cache RPyC service is reachable from untrusted networks.
  2. Firewall the cache service so it is reachable only from the inference components that need it; it must not listen on all interfaces in production.
  3. Treat any Internet-exposed LightLLM multimodal deployment as potentially compromised and review host and container logs for unexpected processes.
  4. Upgrade to a fixed LightLLM release as soon as the vendor publishes one.
  5. Audit other RPyC-based internal services in the same deployment for the same pickle deserialization pattern.

Management note

A serialization boundary that listens on every interface is a single hop from anonymous network access to code execution on GPU infrastructure. Binding the cache service to internal addresses and segmenting it off the public network removes the exposure entirely while awaiting a vendor fix.