{"ok":true,"trend":{"id":442053,"platform":"mastodon","region":"global","key":"🚨 lightllm mass disclosure — 3 cves, no patch cve-2026-103040 (cvss 9.8) — unauthenticated rce, router profiler rpyc cve","title":"🚨 LightLLM Mass Disclosure — 3 CVEs, no patch CVE-2026-103040 (CVSS 9.8) — unauthenticated RCE, router profiler RPyC CVE","url":"https://infosec.exchange/@threataft/117358070526451373","first_seen":"2026-09-30T04:40:06.362649Z","last_seen":"2026-09-30T04:41:05.902259Z","last_rank":7,"peak_rank":1,"last_volume":4,"peak_volume":4,"seen_count":1,"score":0.9434375,"category_hint":"cybersecurity","section":"technology","category":"ai","summary":"Three vulnerabilities in LightLLM, an open-source large language model serving framework, have been disclosed without an available patch. The most serious, CVE-2026-103040, is rated 9.8 and allows unauthenticated remote code execution via the router profiler RPyC interface. A similar flaw, CVE-2026-103041, also rated 9.8, affects the embed cache RPyC service, while CVE-2026-103042, rated 7.5, enables memory exhaustion through the NCCL control channel. Security researchers are urging exposed deployments to restrict network access.","why":"A critical 9.8 unauthenticated remote code execution flaw with no patch poses an immediate risk to anyone running LightLLM instances online.","tone":"negative","entities":["LightLLM","CVE-2026-103040","CVE-2026-103041","CVE-2026-103042","RPyC"],"summarized_at":"2026-09-30T04:41:05.655432Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1183},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Three unpatched critical flaws disclosed in LightLLM","section_name":"Technology","category_name":"AI","timeline":[{"captured_at":"2026-09-30T04:40:06.362649Z","rank":1,"volume":4},{"captured_at":"2026-09-30T04:41:05.902259Z","rank":7,"volume":4}],"posts":[{"platform":"mastodon","url":"https://infosec.exchange/@threataft/117358070526451373","author":"threataft@infosec.exchange","title":null,"snippet":"🚨 LightLLM Mass Disclosure — 3 CVEs, no patch CVE-2026-103040 (CVSS 9.8) — unauthenticated RCE, router profiler RPyC CVE-2026-103041 (CVSS 9.8) — unauthenticated RCE, embed cache RPyC CVE-2026-103042 (CVSS 7.5) — memory exhaustion, NCCL control channel Root cause:…","posted_at":"2026-09-30T04:20:42Z","likes":4}],"elsewhere":[],"window":"7d"}}