In LightLLM through version 1.2.0, multimodal deployments expose an unauthenticated RPyC cache service that deserializes pickle data. A remote attacker can use it to execute arbitrary code, and the flaw is rated CVSS 9.8 (Critical).
What Is It
CVE-2026-103041 is an insecure deserialization flaw (CWE-502) in ModelTC's LightLLM. In multimodal deployments, LightLLM runs an RPyC cache service that has no authentication, has pickle deserialization turned on, and listens on all network interfaces. The code references in the advisory point to the embed cache manager (lightllm/server/embed_cache/manager.py) in v1.2.0.
An attacker can send crafted serialized objects to the cache methods the service exposes. That lets them run arbitrary code with the privileges of the service.
VulnCheck disclosed the issue, and NVD published it on 2026-09-29. The NVD record currently has the status "Deferred."
Why It Matters
VulnCheck scored the flaw CVSS 3.1 9.8 (Critical), with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The CVSS 4.0 score is 9.3 (Critical). The attack:
- works over the network
- is low in complexity
- needs no privileges
- needs no user interaction
A successful attack fully compromises confidentiality, integrity, and availability on the affected service. The service binds to all interfaces, so any deployment that can be reached from the network is exposed.
KEV status: The CISA Known Exploited Vulnerabilities catalog has no entry for this CVE. The source material does not confirm active exploitation.
What's Vulnerable
- Vendor: ModelTC
- Product: LightLLM (
pkg:github/ModelTC/lightllm) - Affected versions: all versions from 0 through 1.2.0 inclusive (semver)
- Condition: multimodal deployments, which expose the RPyC embed cache service
The record does not list any affected CPEs.
Patch Status
The supplied NVD record does not name a fixed version or a vendor patch. CISA has not published a required action, because there is no KEV entry.
The record lists every release up to and including 1.2.0 as affected. Operators should check the upstream repository and GitHub issue #1596 for fix status. They should also treat any network-reachable multimodal LightLLM instance running 1.2.0 or earlier as exposed until a fix is confirmed.
Sources
- NVD – CVE-2026-103041
- VulnCheck Advisory – LightLLM through 1.2.0 Unauthenticated RCE via Embed Cache RPyC Service
- CISA – Known Exploited Vulnerabilities Catalog
- GitHub – ModelTC/LightLLM Issue #1596
- GitHub – LightLLM v1.2.0 embed_cache/manager.py (L29–L31)
- GitHub – LightLLM v1.2.0 embed_cache/manager.py (L66)
- GitHub – ModelTC/LightLLM Repository