External risk intelligence

LightLLM Router Profiler RPyC Unauthenticated Remote Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-103040

The vulnerability exists in a router profiler service within LightLLM that must be explicitly enabled via the --enable_profiling flag. While it exposes an unauthenticated network service, this feature is an optional administrative/diagnostic utility rather than a core public-facing component of a standard deployment, making internet exposure conditional on specific, non-default configuration.

Deserialization

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the LightLLM router profiler service. If this optional service is enabled, it allows unauthenticated attackers to execute arbitrary code remotely by sending specially crafted data to the service. This could potentially lead to a compromise of systems running the affected software.

  • Unauthenticated remote code execution risk.
  • Enables remote code execution if profiling is enabled.
  • Confirm relevance and exposure of the profiling service.

Attack Path

How an attacker could exploit the issue

An attacker can target the LightLLM router profiler service if it's started with a specific flag that enables profiling. This service, accessible over the network without authentication, is susceptible to crafted serialized data sent to its command queue. Successful exploitation allows an attacker to execute arbitrary code on the system.

  • Unauthenticated network access required.
  • Crafted serialized data sent to profiler.
  • Remote code execution.

Live Threat

Current exploitation, exposure, and threat context

A remote code execution vulnerability exists in the LightLLM router profiler service when the `--enable_profiling` flag is set. This service exposes an unauthenticated RPyC server that can be exploited by sending specially crafted serialized objects, potentially allowing an attacker to execute arbitrary code on the affected system.

  • Arbitrary code execution.
  • Unauthenticated RPyC server exposure.
  • System compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

The critical remote code execution vulnerability in LightLLM's router profiler service requires immediate attention from platform or application owners responsible for AI/ML deployments. The first step is to inventory all LightLLM instances, identify those with profiling enabled, and assess their network exposure and business criticality. Subsequent action will depend on this risk assessment, potentially involving vendor coordination, configuration changes, or planned remediation.

  • Platform/Application owners should lead.
  • Verify profiling enabled and network reachability.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is LightLLM?

LightLLM is a high-performance, Python-based inference engine designed for large language models. It provides infrastructure for serving LLMs efficiently, and this specific vulnerability resides in its router profiler component, which developers use to diagnose and monitor model traffic performance.

Why is CVE-2026-103040 considered a deserialization vulnerability?

This CVE is categorized as CWE-502, Deserialization of Untrusted Data. The affected profiler uses the RPyC library to handle incoming data. By using pickle—a format that can execute arbitrary code during deserialization—the service unknowingly transforms a malicious object sent by an attacker into executable commands, bypassing security controls.

Can an attacker trigger this bug without special configuration?

No. The vulnerability is only active if you explicitly start the service using the --enable_profiling flag. If this flag is absent, the vulnerable RPyC server is not initialized, and the service does not listen for the commands that lead to code execution.

How do I know if my system is relevant to this threat?

According to Halo Surface Signal, this vulnerability is not a default exposure. It only affects systems where the optional profiling feature is manually turned on and the service is reachable over a network. If your profiler is restricted to local or trusted management networks, your risk profile is significantly different than those with public-facing instances.

What should I do if I am running LightLLM?

Start by auditing your deployment commands to see if the --enable_profiling flag is in use. If it is enabled, determine if the profiling data is necessary for ongoing operations. If not, disable the flag immediately to remove the service. If you require profiling, ensure the service is isolated from all untrusted network traffic.

References