Description
LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads(). Attackers can reach the Config Server port and send a malicious serialized payload with a __reduce__ method to execute arbitrary code with Config Server process privileges.
Published: 2026-09-14
Score: 9.3 Critical
EPSS: 1.1% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

LightLLM versions through 1.2.0 are vulnerable to unauthenticated remote code execution via, which directly passes the first client frame to pickle.loads(). The endpoint accepts a maliciously crafted payload containing a __reduce__ method, enabling an attacker to execute arbitrary code with the same privileges as the Config Server process. This flaw represents a classic unsafe deserialization vulnerability (CWE‑502) that permits an attacker to compromise the entire system running LightLLM.

Affected Systems

ModelTC LightLLM 1.2.0 and earlier versions are affected. No specific patch version is listed in the data; the issue is resolved in releases newer than 1.2.0.

Risk and Exploitability

The vulnerability scores 9.3 on the CVSS scale, indicating critical impact. EPSS score is 1%, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based; an attacker must reach the Config Server port. The design of the endpoint exposes it to unauthenticated users, making exploitation likely in any environment where the port is reachable and the endpoint remains active.

Generated by OpenCVE AI on September 21, 2026 at 00:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade LightLLM to the latest release that has secured the /visual_register endpoint against unsafe pickle deserialization.
  • Configure firewall rules to restrict access to the Config Server port so that only trusted hosts can communicate with it.
  • If an immediate upgrade is not possible, temporarily disable the /visual_register WebSocket endpoint or reconfigure the server to require authentication before processing frames on that endpoint.

Generated by OpenCVE AI on September 21, 2026 at 00:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Modeltc
Modeltc lightllm
Vendors & Products Modeltc
Modeltc lightllm

Mon, 14 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads(). Attackers can reach the Config Server port and send a malicious serialized payload with a __reduce__ method to execute arbitrary code with Config Server process privileges.
Title LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Config Server Pickle Deserialization
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Modeltc Lightllm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T14:24:32.920Z

Reserved: 2026-09-14T11:04:23.742Z

Link: CVE-2026-90919

cve-icon Vulnrichment

Updated: 2026-09-14T14:24:27.430Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T12:17:51.807

Modified: 2026-09-23T17:17:44.447

Link: CVE-2026-90919

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:45:08Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data