Impact
The vulnerability allows an unauthenticated attacker to register arbitrary nodes through the /pd_register WebSocket endpoint by sending crafted JSON payloads that bypass peer address validation. This bypass can reveal sensitive prompts sent to the master, cause service disruption by replacing legitimate nodes, or force the PD Master to forward requests to internal network addresses, potentially exposing internal resources. The weakness is a classic authentication bypass (CWE‑306).
Affected Systems
The flaw is present in ModelTC LightLLM versions up to and including 1.2.0. No other versions were identified as affected in the current data set.
Risk and Exploitability
The CVSS base score of 9.3 marks this a critical vulnerability, yet the EPSS score of less than 1% suggests low current exploitation activity. The issue is not listed in the CISA KEV catalog. Attackers can exploit it remotely by connecting to the WebSocket endpoint, sending a crafted payload, and immediately gaining the ability to register any node. Because the endpoint accepts connections without authentication, the barrier to exploitation is very low.
OpenCVE Enrichment