---
id: CVE-2026-103041
title: >-
  LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC
  cache service with pickle deserialization enabled on all interfaces
summary: >-
  LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC
  cache service with pickle deserialization enabled on all interfaces. Attackers
  can send crafted serialized objects to exposed cache methods to execute
  arbitrary…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
vendor: ModelTC
product: LightLLM
affected:
  - LightLLM <= 1.2.0
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T23:17:21.760'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103041'
references:
  - url: 'https://github.com/ModelTC/LightLLM'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ModelTC/LightLLM/issues/1596'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/embed_cache/manager.py#L29-L31
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/embed_cache/manager.py#L66
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/lightllm-through-1.2.0-unauthenticated-remote-code-execution-via-embed-cache-rpyc-service
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T23:52:50.535Z'
---

## Overview

LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
