Impact
LightLLM versions through 1.2.0 are vulnerable to unauthenticated remote code execution via, which directly passes the first client frame to pickle.loads(). The endpoint accepts a maliciously crafted payload containing a __reduce__ method, enabling an attacker to execute arbitrary code with the same privileges as the Config Server process. This flaw represents a classic unsafe deserialization vulnerability (CWE‑502) that permits an attacker to compromise the entire system running LightLLM.
Affected Systems
ModelTC LightLLM 1.2.0 and earlier versions are affected. No specific patch version is listed in the data; the issue is resolved in releases newer than 1.2.0.
Risk and Exploitability
The vulnerability scores 9.3 on the CVSS scale, indicating critical impact. EPSS score is 1%, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based; an attacker must reach the Config Server port. The design of the endpoint exposes it to unauthenticated users, making exploitation likely in any environment where the port is reachable and the endpoint remains active.
OpenCVE Enrichment