Back to Intelligence

CVE-2026-102911, CVE-2026-103040, CVE-2026-103041: Critical LLM Infrastructure RCE — Detection and Remediation Guide

SA
Security Arsenal Team
September 30, 2026
11 min read

In the last 72 hours, NVD published three critical, network-vector vulnerabilities affecting LLM tooling — the kind of infrastructure that is proliferating across enterprise environments faster than most security teams can inventory it. The most severe, CVE-2026-102911 (CVSS 9.9), is an OS command injection flaw in the wiki_capture_source MCP tool shipped with zosmaai pi-llm-wiki up to version 0.11.7. The remaining two — CVE-2026-103040 and CVE-2026-103041 (both CVSS 9.8) — affect LightLLM through version 1.2.0 and expose unauthenticated remote code execution paths in the router profiler service and the RPyC cache in multimodal deployments, respectively.

This is the pattern we've been warning clients about since MCP servers and self-hosted LLM inference stacks started showing up in production: developer-grade tooling, built for trusted lab environments, deployed on network segments with real exposure. All three of these vulnerabilities are remotely exploitable without authentication in their default postures, all three lead to code execution in the context of the LLM service, and all three sit on hosts that typically hold API keys, model weights, vector store credentials, and — increasingly — agentic tool access to internal systems. If your organization runs LightLLM or pi-llm-wiki anywhere reachable beyond localhost, treat this as an immediate patch-and-hunt event.

Technical Analysis

CVE-2026-102911 — OS Command Injection in pi-llm-wiki wiki_capture_source MCP Tool (CVSS 9.9)

Affected product: zosmaai pi-llm-wiki, versions up to and including 0.11.7.

The flaw lives in an unknown function within mcp/index.ts, the file implementing the wiki_capture_source MCP tool. The tool accepts a url argument that is passed, without adequate sanitization, into an OS command execution context. An attacker who can reach the MCP server can manipulate the url argument to inject arbitrary shell commands — classic CWE-78 command injection, delivered over a modern AI-tooling interface.

From a defender's perspective, the attack chain is straightforward:

  1. Attacker identifies an exposed MCP server endpoint running pi-llm-wiki ≤ 0.11.7 (these servers commonly listen on HTTP/SSE transports, and many teams bind them to 0.0.0.0 so agents across the network can reach them).
  2. Attacker invokes the wiki_capture_source tool with a crafted url value containing shell metacharacters or command substitution (e.g., ;, |, backticks, $(...) sequences).
  3. The Node.js/TypeScript process handling the MCP request executes the injected command with its own privileges.
  4. Post-exploitation: the compromised process typically has access to the wiki's data, environment variables (frequently containing LLM API keys), and any downstream tool integrations configured in the MCP server.

Per the advisory, the security issue has been publicly published and may be used — meaning exploit details are available and weaponization should be assumed imminent if not already occurring. The remediation path indicated is upgrading beyond the affected 0.11.7 line.

CVE-2026-103040 — Unauthenticated Code Execution in LightLLM Router Profiler Service (CVSS 9.8)

Affected product: LightLLM through version 1.2.0.

LightLLM is a Python-based LLM inference and serving framework. Its router component exposes a profiler service intended for performance diagnostics. Through version 1.2.0, this profiler service can be reached without authentication and abused to achieve code execution on the serving host. In practical terms: any host with the LightLLM router bound to a network interface is offering unauthenticated RCE to anyone who can route to the profiler endpoint. GPU inference hosts are high-value targets — they tend to be flat-networked, lightly monitored, and loaded with credentials for model registries and storage backends.

CVE-2026-103041 — Unauthenticated RPyC Cache Exposure in LightLLM Multimodal Deployments (CVSS 9.8)

Affected product: LightLLM through version 1.2.0, multimodal deployments.

Multimodal configurations of LightLLM expose an RPyC (Remote Python Call) cache service without authentication. RPyC, in its classic configuration, is effectively remote Python execution by design — a client that can connect can invoke arbitrary Python on the server side. An unauthenticated RPyC listener (default RPyC classic port is TCP 18812, though deployments vary) on a multimodal LightLLM node is functionally equivalent to an unauthenticated remote Python shell. Exploitation requires nothing more than network reachability and the RPyC client library.

Exploitation Status

  • CVE-2026-102911: Advisory states the issue has been published and "may be used." Treat public exploitability as confirmed; assume scanning and opportunistic exploitation will follow quickly given the popularity of MCP tooling.
  • CVE-2026-103040 / CVE-2026-103041: Publicly documented as unauthenticated code execution / exposure. At time of writing, no confirmed in-the-wild campaign has been reported and none of the three CVEs have appeared in CISA KEV — but unauthenticated network RCE in Python services is among the fastest vulnerability classes to be weaponized. Do not wait for KEV inclusion to act.

Detection & Response

The highest-fidelity detection signal across all three CVEs is the same: an LLM serving or MCP process spawning a shell or unexpected child process, and unexpected network connections to LLM service ports. Inference servers and MCP tools do not normally launch sh, bash, curl, wget, or Python subprocesses against internal targets. These behaviors are low-noise in well-managed environments and should page immediately.

YAML
---
title: MCP or LLM Server Process Spawning Shell - Possible Command Injection
description: Detects Node.js or Python LLM/MCP server processes (pi-llm-wiki, LightLLM) spawning shells or command execution utilities, consistent with CVE-2026-102911 OS command injection via the wiki_capture_source MCP tool and LightLLM RCE.
id: 3f9a2b71-6c4e-4d8a-9b12-7e5f0a1c2d34
status: experimental
references:
  - https://nvd.nist.gov/vuln/detail/CVE-2026-102911
  - https://nvd.nist.gov/vuln/detail/CVE-2026-103040
  - https://nvd.nist.gov/vuln/detail/CVE-2026-103041
  - https://attack.mitre.org/techniques/T1059/004/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.execution
  - attack.t1059.004
  - attack.initial_access
  - attack.t1190
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
      - '/node'
      - '/python'
      - '/python3'
      - '/uvicorn'
      - '/gunicorn'
      - '/tsx'
  selection_parent_cli:
    ParentCommandLine|contains:
      - 'llm'
      - 'mcp'
      - 'pi-llm-wiki'
      - 'lightllm'
      - 'index.ts'
  selection_child:
    Image|endswith:
      - '/sh'
      - '/bash'
      - '/dash'
      - '/curl'
      - '/wget'
      - '/nc'
      - '/ncat'
      - '/python'
      - '/python3'
      - '/base64'
      - '/chmod'
  condition: selection_parent and selection_parent_cli and selection_child
falsepositives:
  - LLM frameworks that legitimately shell out for model compilation or tokenizer tooling - baseline per host and tune
level: high
---
title: Shell Metacharacters in MCP Tool URL Argument
description: Detects shell injection metacharacters in command lines or logged tool invocations referencing the wiki_capture_source MCP tool url argument, indicating exploitation attempts against CVE-2026-102911.
id: 8b1c4e92-2f7a-4b3d-a6e9-1c5d8f0b3a45
status: experimental
references:
  - https://nvd.nist.gov/vuln/detail/CVE-2026-102911
  - https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.initial_access
  - attack.t1190
  - attack.execution
  - attack.t1059
logsource:
  category: process_creation
  product: linux
detection:
  selection_tool:
    CommandLine|contains:
      - 'wiki_capture_source'
  selection_injection:
    CommandLine|contains:
      - ';'
      - '&&'
      - '||'
      - '`'
      - '$('
      - '| sh'
      - '| bash'
  condition: selection_tool and selection_injection
falsepositives:
  - Unlikely - legitimate wiki capture URLs should never contain shell operators
level: critical
---
title: Unauthenticated Connection to RPyC or LightLLM Profiler Service
description: Detects inbound network connections to RPyC default ports or LightLLM router/profiler services from non-localhost sources, indicating potential exploitation of CVE-2026-103040 or CVE-2026-103041.
id: c47d2f18-9a3b-4e6c-b1d5-5f2a7c9e4d61
status: experimental
references:
  - https://nvd.nist.gov/vuln/detail/CVE-2026-103040
  - https://nvd.nist.gov/vuln/detail/CVE-2026-103041
  - https://attack.mitre.org/techniques/T1190/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.initial_access
  - attack.t1190
  - attack.discovery
  - attack.t1046
logsource:
  category: network_connection
  product: linux
detection:
  selection_ports:
    DestinationPort:
      - 18812
      - 18861
      - 18878
  selection_proc:
    Image|endswith:
      - '/python'
      - '/python3'
  selection_not_local:
    SourceIp|cidr:
      - '0.0.0.0/0'
  filter_loopback:
    SourceIp:
      - '127.0.0.1'
      - '::1'
  condition: selection_ports and selection_proc and selection_not_local and not filter_loopback
falsepositives:
  - Legitimate distributed LightLLM worker traffic - restrict by known-good peer IP ranges
level: high
KQL — Microsoft Sentinel / Defender
// Hunt for LLM/MCP server processes spawning shells or network utilities
// Covers CVE-2026-102911 (MCP command injection) and LightLLM RCE behavior
// Works against Syslog, CEF-ingested EDR, and Defender for Endpoint on Linux
union isfuzzy=true
    (Syslog
    | where Facility =~ "user" or Facility =~ "daemon"
    | where ProcessName has_any ("node", "python", "python3", "uvicorn", "tsx")
       or SyslogMessage has_any ("lightllm", "mcp", "pi-llm-wiki", "wiki_capture_source")
    | where SyslogMessage has_any ("/bin/sh", "/bin/bash", "curl ", "wget ", "nc -", "$(", "`", ";sh", "|sh")
    | project TimeGenerated, Computer, ProcessName, SyslogMessage, SeverityLevel),
    (DeviceProcessEvents
    | where InitiatingProcessFileName in~ ("node", "python", "python3", "uvicorn", "gunicorn", "tsx")
       or InitiatingProcessCommandLine has_any ("lightllm", "mcp", "pi-llm-wiki", "index.ts")
    | where FileName in~ ("sh", "bash", "dash", "curl", "wget", "nc", "ncat", "base64")
    | project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, AccountName),
    (DeviceNetworkEvents
    | where RemotePort in (18812, 18861, 18878) or (RemotePort between (8000 .. 8099) and InitiatingProcessFileName =~ "python3")
    | where RemoteIP !startswith "127." and RemoteIP != "::1"
    | project TimeGenerated, DeviceName, LocalIP, LocalPort, RemoteIP, RemotePort, InitiatingProcessFileName, InitiatingProcessCommandLine)
| sort by TimeGenerated desc
VQL — Velociraptor
-- Security Arsenal: Hunt LLM/MCP RCE artifacts (CVE-2026-102911, CVE-2026-103040/41)
-- Identify suspicious child processes of LLM serving processes and exposed listeners

-- Part 1: Node/Python LLM processes with shell-like children or injection strings
SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE (Exe =~ '(node|python3?|uvicorn|tsx)$'
       OR CommandLine =~ '(?i)(lightllm|mcp|pi-llm-wiki|index\\.ts)')
  AND CommandLine =~ '(?i)(;|&&|\\|\\||`.*`|\\$\\(|/bin/(ba)?sh|curl |wget |nc -)'

-- Part 2: Listening sockets on RPyC / LLM serving ports bound to non-loopback
SELECT Pid, Name, Family, Status, Laddr, Raddr
FROM netstat()
WHERE Status =~ 'LISTEN'
  AND (Laddr.Port =~ '^(18812|18861|18878|8000|8080)$')
  AND Laddr.IP =~ '^(0\\.0\\.0\\.0|::)'
  AND Name =~ '(?i)(python|node)'
Bash / Shell
#!/bin/bash
# Security Arsenal - LLM infra triage & hardening (CVE-2026-102911 / -103040 / -103041)
# Run on any host suspected of running pi-llm-wiki or LightLLM.

echo "=== [1] Check pi-llm-wiki version (vuln if <= 0.11.7) ==="
find / -name "package.json" -path "*pi-llm-wiki*" 2>/dev/null | while read -r f; do
  echo "Found: $f"; grep -E '"version"' "$f"
done
npm ls -g pi-llm-wiki 2>/dev/null

echo "=== [2] Check LightLLM version (vuln if <= 1.2.0) ==="
python3 -c "import lightllm, sys; print('lightllm version:', getattr(lightllm,'__version__','unknown'))" 2>/dev/null \
  || pip show lightllm 2>/dev/null | grep -i version

echo "=== [3] Identify exposed LLM/MCP listeners bound to 0.0.0.0 ==="
ss -tlnp 2>/dev/null | grep -E ':(8000|8080|18812|18861|18878|3000|5000)\b' | grep -E '(0\.0\.0\.0|::|\*)'

echo "=== [4] Audit for suspicious child processes of node/python LLM services ==="
ps auxf | grep -E '(node|python)' | grep -E '(sh|bash|curl|wget|nc )' | grep -v grep

echo "=== [5] Emergency mitigation: block unauthenticated service ports at host firewall ==="
# Restrict RPyC and profiler ports to localhost / known management subnet only.
# ADJUST the allowed source CIDR to your actual inference cluster peers BEFORE running.
ALLOWED_CIDR="10.0.0.0/8"
for port in 18812 18861 18878; do
  iptables -C INPUT -p tcp --dport "$port" -s "$ALLOWED_CIDR" -j ACCEPT 2>/dev/null || \
    iptables -I INPUT -p tcp --dport "$port" -s "$ALLOWED_CIDR" -j ACCEPT
  iptables -C INPUT -p tcp --dport "$port" -j DROP 2>/dev/null || \
    iptables -I INPUT -p tcp --dport "$port" -j DROP
done

echo "=== [6] If patching is not yet possible: disable the vulnerable MCP tool ==="
echo "Remove or comment out the wiki_capture_source tool registration in mcp/index.ts"
echo "and restart the MCP server, OR take the pi-llm-wiki service offline until upgraded."

echo "=== DONE. Review output, then upgrade pi-llm-wiki and LightLLM per vendor advisories. ==="

Remediation

CVE-2026-102911 (pi-llm-wiki):

  • Upgrade pi-llm-wiki beyond the vulnerable 0.11.7 release line immediately, per the vendor advisory referenced in the NVD entry. The advisory states upgrading to the fixed version resolves the flaw.
  • Until patched, disable the wiki_capture_source MCP tool entirely by removing its registration in mcp/index.ts, or take the MCP server offline.
  • Verify MCP servers are bound to localhost or fronted by an authenticated reverse proxy. No MCP server should ever be reachable from untrusted networks — the protocol's trust model assumes a controlled client.
  • Audit logs for prior invocations of wiki_capture_source with unusual url values, and check for child processes of the MCP server as shown above.

CVE-2026-103040 / CVE-2026-103041 (LightLLM):

  • Upgrade LightLLM past version 1.2.0 as soon as a fixed release is available; track the LightLLM GitHub repository and the NVD entries (CVE-2026-103040, CVE-2026-103041) for patch confirmation.
  • Immediately network-segment LightLLM hosts. The router profiler service and the RPyC cache must not be reachable outside the inference cluster. Enforce host firewall rules restricting these ports to known peer IPs only (see script above).
  • For multimodal deployments, confirm whether the RPyC cache listener is bound to a routable interface; if so, treat the host as potentially compromised and hunt before re-exposing it.
  • Add authentication and TLS in front of the router service (reverse proxy with mTLS is the pragmatic option) until the vendor ships native controls.

Strategic actions for your LLM estate:

  • Inventory every MCP server and LLM serving framework in your environment. In our IR engagements over the past year, shadow AI infrastructure has consistently been the least inventoried, least patched, and least monitored asset class.
  • Apply the same vulnerability-management SLAs to AI tooling that you apply to VPN concentrators and hypervisors: critical, network-exploitable, unauthenticated RCE means patch or isolate within days, not quarters.
  • Monitor for these CVEs' inclusion in CISA KEV and treat KEV deadlines as the ceiling, not the target, for remediation.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.