LightLLM Mass Disclosure — 2 CVSS 9.8 Unauthenticated RCE in LLM Serving Framework
This story is from 2026-09-30. It is preserved in the archive; the latest stories are on the live feed.
Two unauthenticated CVSS 9.8 RCEs in LightLLM — the LLM serving framework used with LLaMA, Mistral, and Qwen deployments. No patch confirmed. All versions through 1.2.0 are affected. The CVEs CVE CVSS Type Vector CVE-2026-103040 9.8 Pickle deserialization RCE Router profiler RPyC service CVE-2026-1…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-30 04:20 · DEV Community — AI
LightLLM Mass Disclosure — 2 CVSS 9.8 Unauthenticated RCE in LLM Serving Framework