Modeltc Lightllm vulnerabilities
10 known vulnerabilities affecting modeltc/lightllm.
Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-26220P2CRITICALCVSS 9.3≤ 1.1.02026-02-17
CVE-2026-26220 [CRITICAL] CWE-502 CVE-2026-26220: LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in P
LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) disaggregation mode. The PD master node exposes WebSocket endpoints that receive binary frames and pass the data directly to pickle.loads() without authentication or validation. A remote attacker who can reach the PD master can se
nvd
CVE-2026-103040P2CRITICALCVSS 9.8≤ 1.2.02026-09-29
CVE-2026-103040 [CRITICAL] CWE-502 CVE-2026-103040: LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service
LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to the profiler command queue.
nvd
CVE-2026-90919P2CRITICALCVSS 9.8≤ 1.2.02026-09-14
CVE-2026-90919 [CRITICAL] CWE-502 CVE-2026-90919: LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthe
LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads(). Attackers can reach the Config Server port and send a malicious serialized payload with a __reduce__ method to execute arbitrary code with Co
nvd
CVE-2026-93839P2CRITICALCVSS 9.8≤ 1.2.02026-09-18
CVE-2026-93839 [CRITICAL] CWE-306 CVE-2026-93839: LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket
LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate
nvd
CVE-2026-103395P2CRITICALCVSS 9.8≤ 1.2.02026-09-30
CVE-2026-103395 [CRITICAL] CWE-502 CVE-2026-103395: LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pic
LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with __reduce__ methods to execute arbitrary code with service account privileges.
nvd
CVE-2026-96560P2CRITICALCVSS 9.8≤ 1.2.02026-09-23
CVE-2026-96560 [CRITICAL] CWE-502 CVE-2026-96560: LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when
LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauthenticated RPyC control channel that deserializes attacker-supplied data. Attackers can send malicious pickled objects to the exposed RPyC ThreadedServer to execute arbitrary code with the pr
nvd
CVE-2026-103041P2CRITICALCVSS 9.8≤ 1.2.02026-09-29
CVE-2026-103041 [CRITICAL] CWE-502 CVE-2026-103041: LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pick
LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges.
nvd
CVE-2026-103270P3HIGHCVSS 7.5≤ 1.2.02026-09-30
CVE-2026-103270 [HIGH] CWE-306 CVE-2026-103270: LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without a
LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, and /init_weights_update_group to disrupt inference operations and wedge workers on deployments started with --enable_rl.
nvd
CVE-2026-103042P3HIGHCVSS 7.5≤ 1.2.02026-09-29
CVE-2026-103042 [HIGH] CWE-770 CVE-2026-103042: LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when s
LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker memory. Attackers can call the exposed_set_value method to store unbounded key-value pairs without size limits, causing the worker process to crash and
nvd
CVE-2026-103243P3MEDIUMCVSS 5.8≤ 1.2.02026-09-30
CVE-2026-103243 [MEDIUM] CWE-918 CVE-2026-103243: LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal endpoints,
LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal endpoints, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply arbitrary URLs to fetch internal resources, with vision model processing disclosing content or error responses revealing internal network topology.
nvd