Advisory · CVE-2026-103041
Unauthenticated RCE in LightLLM via embed cache RPyC service
LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization on all interfaces, letting attackers send crafted serialized objects to execute arbitrary code.
- Vendor
- ModelTC
- Product
- LightLLM
- Identifier / CWE
- CVE-2026-103041
CWE-502 - Action timing
- Immediate
Explain it like I’m five
LightLLM's multimodal cache works like a loading dock that accepts sealed packages from anyone and opens every one. An attacker drops off a package that turns into shell commands when the lid comes off.
- 01Multimodal deployment
A LightLLM multimodal deployment starts the embed cache service, binding its RPyC interface on all network interfaces.
- 02Cache service exposed
The cache service accepts unauthenticated connections and uses Python pickle deserialization on incoming objects.
- 03Crafted object sent
A remote attacker sends a crafted serialized object to an exposed cache method.
- 04Payload executes
Deserialization runs the attacker's code with the privileges of the LightLLM service.
What happened
LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers send crafted serialized objects to exposed cache methods, and deserialization executes arbitrary code with the privileges of the LightLLM service.
No patch release is documented in the disclosure at the time of writing; the advisory states only that LightLLM through 1.2.0 is affected.
What to do
- Inventory LightLLM multimodal deployments and confirm whether the embed cache RPyC service is reachable from untrusted networks.
- Firewall the cache service so it is reachable only from the inference components that need it; it must not listen on all interfaces in production.
- Treat any Internet-exposed LightLLM multimodal deployment as potentially compromised and review host and container logs for unexpected processes.
- Upgrade to a fixed LightLLM release as soon as the vendor publishes one.
- Audit other RPyC-based internal services in the same deployment for the same pickle deserialization pattern.
Management note
A serialization boundary that listens on every interface is a single hop from anonymous network access to code execution on GPU infrastructure. Binding the cache service to internal addresses and segmenting it off the public network removes the exposure entirely while awaiting a vendor fix.