rootpwn

critical · CVSS v3 9.8 · CVSS v4 9.3

CVE-2026-96560

LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_t…

Description

LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauthenticated RPyC control channel that deserializes attacker-supplied data. Attackers can send malicious pickled objects to the exposed RPyC ThreadedServer to execute arbitrary code with the privileges of the LightLLM service account.

Scores

Severity
critical
CVSS v2
10
CVSS v3
9.8
CVSS v4
9.3
EPSS

← All CVEs