AINewsnow

LightLLM Mass Disclosure — 2 CVSS 9.8 Unauthenticated RCE in LLM Serving Framework

This story is from 2026-09-30. It is preserved in the archive; the latest stories are on the live feed.

Two unauthenticated CVSS 9.8 RCEs in LightLLM — the LLM serving framework used with LLaMA, Mistral, and Qwen deployments. No patch confirmed. All versions through 1.2.0 are affected. The CVEs CVE CVSS Type Vector CVE-2026-103040 9.8 Pickle deserialization RCE Router profiler RPyC service CVE-2026-1…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-09-30 04:20 · DEV Community — AI
    LightLLM Mass Disclosure — 2 CVSS 9.8 Unauthenticated RCE in LLM Serving Framework

More stories

  1. Qwen 3.8 27B vs Qwen 3.8 Flash Next and time to complete a coding task. — r/LocalLLaMA
  2. Help me plan a Qwen 3.8 Flash Next install on a 5090 + 64gb DDR5 system — r/LocalLLM
  3. Qwen 3.8 27B on a single 3090: 114 min solo, 43 min as a worker under a GPT 6.1 SOL orchestrator — r/LocalLLM
  4. A company ran 8 identical AI societies for weeks with different models and just published what happened. Some of it is genuinely unsettling. — r/artificial
  5. Qwen 3.8 27B on a 3090 with a Sonnet 5.5 as a planner: 2.7x cheaper, real numbers — r/LocalLLM
  6. Qwen 3.8 is a workhorse — r/LocalLLaMA
  7. vulkan: fuse qwen4exp's SCALE -> SIGMOID -> SCALE -> hc_post chain by fxgsell · Pull Request #29520 · ggml-org/llama.cpp — r/LocalLLaMA
  8. Adding logit penalty for "wait", "maybe" and "perhaps" to Qwen models improves their accuracy — r/LocalLLaMA

Get the daily brief of stories like this at 6:30 every morning →