CVE-2026-103041 - LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Embed Cache RPyC Service
CVE ID :CVE-2026-103041 Published : Sept. 29, 2026, 11:17 p.m. | 58 minutes ago Description :LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to...