CVE-2026-103040 LightLLM 远程代码执行漏洞
影响攻击者可远程执行任意代码
LightLLM 1.2.0 及之前版本的 router profiler 服务在启用 --enable_profiling 标志时存在远程代码执行漏洞。该服务暴露了一个未认证的 RPyC 服务器,并启用了 pickle 反序列化,攻击者可通过向 profiler 命令队列发送恶意序列化对象来执行任意代码。
影响范围
LightLLM 1.2.0 及之前版本,且 router profiler 服务以 --enable_profiling 标志启动。
漏洞详情
漏洞类型为不安全的反序列化导致远程代码执行。成因是 profiler 服务使用 RPyC 并启用 pickle 反序列化,且未实施认证。攻击者无需认证即可连接该服务,向命令队列发送精心构造的 pickle 序列化数据,触发反序列化过程从而执行任意代码。
利用条件与风险
利用前提是目标 LightLLM 实例启用了 --enable_profiling 且 profiler 服务网络可达。由于无需认证且 CVSS 评分高达 9.8,实战风险极高,可导致服务器被完全控制。
修复建议
官方修复方案暂无公开信息。临时缓解措施包括:避免在生产环境启用 --enable_profiling,或通过防火墙/网络策略限制对 profiler 服务端口的访问。
LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with –enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to the profiler command queue.