CVE-2026-103040 is a critical (CVSS 9.8) unauthenticated remote code execution flaw in LightLLM through version 1.2.0. It is caused by pickle deserialization in the router profiler's RPyC service.
What Is It
LightLLM is ModelTC's LLM inference framework. It has a remote code execution vulnerability in its router profiler service. The vulnerable service only runs when LightLLM is started with the --enable_profiling flag. In that mode, the profiler exposes an RPyC server with no authentication and with pickle deserialization enabled. An attacker can run arbitrary code by sending crafted serialized objects to the profiler command queue.
The weakness is classified as CWE-502 (Deserialization of Untrusted Data). VulnCheck disclosed the issue and it was published to NVD on 2026-09-29. NVD currently lists its status as "Deferred."
Why It Matters
VulnCheck scores this 9.8 CRITICAL under CVSS 3.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and 9.3 CRITICAL under CVSS 4.0. That means:
- Network-reachable: the attacker needs no local access.
- Low complexity: there are no special attack requirements.
- No privileges or user interaction: the RPyC server has no authentication.
- High impact: the CVSS vector rates confidentiality, integrity and availability impact as High, so successful exploitation could seriously compromise all three.
When the profiler is on, an attacker who can reach the RPyC service may be able to run code on the host serving the model.
Exploitation status: There is no CISA KEV entry for this CVE. KEV does not confirm active exploitation, and the CVSS 4.0 exploit maturity field is "Not Defined."
What's Vulnerable
- Vendor: ModelTC
- Product: LightLLM (
pkg:github/ModelTC/lightllm) - Affected versions: all versions from 0 through 1.2.0 (semver)
- Condition: only deployments started with
--enable_profiling, because that flag starts the router profiler service
The vulnerable code is in lightllm/server/router/profiler_service.py in the v1.2.0 tag (lines 32–34 and 46–50).
Patch Status
The source data does not name a fixed version. The NVD record lists every version through 1.2.0 as affected and gives no patched release. Neither CISA KEV nor NVD specifies a required action.
Operators should check the upstream GitHub issue (#1597) and the VulnCheck advisory for remediation updates. They should also find any LightLLM instances running with --enable_profiling, since the vulnerable service is only exposed in that configuration.