GHSA-c838-68vr-jxfwCriticalCVSS 9.8

LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler...

Published
September 30, 2026
Last Modified
September 30, 2026

🔗 CVE IDs covered (1)

📋 Description

LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to the profiler command queue.

🔗 References (7)