interesting · Edge — RCE
A reachable LightLLM visual-only node executes unauthenticated pickle payloads as its service account.
Affects
LightLLM, a Linux-based distributed large-model inference server; this path is present on dedicated visual-only multimodal nodes.
The optional visual-only RPyC service binds without an authenticator and enables pickle deserialization; a crafted remote_infer_images argument executes before type handling.
Detail and 4 sources
The new scope evidence is second-host reproduction, which establishes a network path rather than only local execution. Exposure remains limited to nodes launched in visual-only mode with the port reachable.
Sources
Code / PoC[BUG] Unauthenticated RCE via pickle deserialization in the visual_only RPyC service · Issue #1610 · ModelTC/LightLLMCode / PoCLightLLM/lightllm/server/visualserver/objs.py at v1.2.0 · ModelTC/LightLLM · GitHubCode / PoCLightLLM/lightllm/server/visualserver/visual_only_manager.py at v1.2.0 · ModelTC/LightLLM · GitHubSecondaryLightLLM Visual Nodes Expose Unauthenticated Pickle RCE (CVE-2026-103395), With No Fix Yet