ModelTC LightLLM

9 known vulnerabilities in ModelTC LightLLM, 6 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-103395 CVSS 9.3 critical LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes…
  • CVE-2026-103270 CVSS 8.7 high LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated…
  • CVE-2026-103243 CVSS 6.9 medium LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal endpoints, allowing unauthenticated attackers to…
  • CVE-2026-103042 CVSS 8.7 high LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl…
  • CVE-2026-103041 CVSS 9.3 critical LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all…
  • CVE-2026-103040 CVSS 9.3 critical LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling…
  • CVE-2026-96560 CVSS 9.3 critical LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl…
  • CVE-2026-93839 CVSS 9.3 critical LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated…
  • CVE-2026-90919 CVSS 9.3 critical LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket…