rootpwn

high · CVSS v3 7.5 · CVSS v4 8.7

CVE-2026-103270

LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks…

Description

LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, and /init_weights_update_group to disrupt inference operations and wedge workers on deployments started with --enable_rl.

Scores

Severity
high
CVSS v2
7.8
CVSS v3
7.5
CVSS v4
8.7
EPSS
—

← All CVEs