CVE-2026-103395

CVE-2026-103395 published: LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with _...

View full NVD advisory → ← Back to CVE watch