⌁AI·CYBER·BRIEF▌

#LightLLM

Vulnerabilities8 min read

Ten advisories, no patched version: LightLLM's internal services are open by default

Ten CVEs now list ModelTC's LightLLM inference server as affected, nine of them through 1.2.0 — its newest release. Six are unauthenticated remote code execution. There is no version to upgrade to.

LightLLMModelTCCVE-2026-103395