[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#CVE-2026-103395

newsCRITICAL 9.8

CVE-2026-103395: Unauthenticated RPyC Service Exposes LightLLM to Arbitrary Code Execution

A critical vulnerability in LightLLM through version 1.2.0 allows unauthenticated attackers to execute arbitrary code with service account privileges. The flaw is due to an exposed RPyC service with allow_pickle enabled, which deserializes attacker-supplied arguments. A CVSS score of 9.8 indicates the severity of this vulnerability.

Oct 1, 20261 source