Remote Code Execution Vulnerability in LightLLM by ModelTC
CVE-2026-96560
9.3CRITICAL
What is CVE-2026-96560?
LightLLM versions prior to 1.2.0 are vulnerable to a remote code execution issue arising from an exposed RPyC control channel. This vulnerability occurs when the KV-transfer worker is initiated with the --pd_trans_mode nccl, allowing attackers to exploit unauthenticated access to deserialized malicious pickled objects. By sending specially crafted data to the RPyC ThreadedServer, attackers can execute arbitrary code under the privileges of the LightLLM service account, posing serious risks to system integrity and confidentiality.
Affected Version(s)
LightLLM 0 <= 1.2.0
