CVE-2026-103395 - LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Visual-Only RPyC Service
CVE ID :CVE-2026-103395 Published : 30. September 2026 15:22 | 1 Stunde, 16 Minuten ago Description :LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method....