{"ok":true,"trend":{"id":420577,"platform":"mastodon","region":"global","key":"🚨 cve-2026-103040 — cvss 9.3 critical lightllm through 1.2.0 contains a remote code execution vulnerability in the route","title":"🚨 CVE-2026-103040 — CVSS 9.3 CRITICAL LightLLM through 1.2.0 contains a remote code execution vulnerability in the route","url":"https://mastodon.social/@stemshop/117357084329340556","first_seen":"2026-09-30T00:34:05.132850Z","last_seen":"2026-09-30T00:34:05.132850Z","last_rank":3,"peak_rank":3,"last_volume":0,"peak_volume":0,"seen_count":1,"score":0.54296875,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A critical remote code execution flaw, tracked as CVE-2026-103040 with a CVSS score of 9.3, has been disclosed in LightLLM through version 1.2.0. The vulnerability sits in the router profiler service when launched with the --enable_profiling flag, which exposes an unauthenticated RPyC server with pickle deserialization enabled, letting attackers run arbitrary code. Security teams are being urged to check whether their deployments are affected.","why":"Security teams are alerting each other to a newly disclosed critical vulnerability that could expose AI serving infrastructure to takeover","tone":"negative","entities":["LightLLM","CVE-2026-103040"],"summarized_at":"2026-09-30T00:34:37.338446Z","meta":{"tag":"cybersecurity","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1176},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Critical RCE vulnerability disclosed in LightLLM","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-09-30T00:34:05.132850Z","rank":3,"volume":0}],"posts":[{"platform":"mastodon","url":"https://mastodon.social/@stemshop/117357084329340556","author":"stemshop","title":null,"snippet":"🚨 CVE-2026-103040 — CVSS 9.3 CRITICAL LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing…","posted_at":"2026-09-30T00:09:54.774000Z","likes":0}],"elsewhere":[],"window":"7d"}}