GHSA-mw2v-h3wh-mp72CriticalCVSS 9.8

LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with...

Published
September 30, 2026
Last Modified
September 30, 2026

🔗 CVE IDs covered (1)

📋 Description

LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with reduce methods to execute arbitrary code with service account privileges.

🔗 References (7)