CVE-2026-96560

LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauthenticated RPyC control channel that deserializes attacker-supplied data. Attackers can send malicious pickled objects to the exposed RPyC ThreadedServer to execute arbitrary code with the privileges of the LightLLM service account.

  • Published Sep 23, 2026
  • CVSS 9.3 critical
  • 0.7% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-96560 at the National Vulnerability Database