CyberRota Analysis
AI-GeneratedLightLLM versions up to 1.2.0 are vulnerable due to an unauthenticated RPyC service that allows remote code execution through deserialization of attacker-supplied arguments. This vulnerability can be exploited to execute arbitrary code with service account privileges, posing a critical risk to any deployment using this software. Organizations utilizing LightLLM should prioritize immediate remediation to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with __reduce__ methods to execute arbitrary code with service account privileges.