{"id":"CVE-2026-96560","published":"2026-09-23T14:17:11.073","lastModified":"2026-09-23T17:17:49.440","description":"LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauthenticated RPyC control channel that deserializes attacker-supplied data. Attackers can send malicious pickled objects to the exposed RPyC ThreadedServer to execute arbitrary code with the privileges of the LightLLM service account.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-502"],"vendors":[],"products":[],"references":[{"url":"https://github.com/ModelTC/LightLLM/issues/1590","tags":[]},{"url":"https://github.com/ModelTC/lightllm","tags":[]},{"url":"https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/kv_transporter.py#L20-L36","tags":[]},{"url":"https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/nccl_kv_transporter.py#L247-L249","tags":[]},{"url":"https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/nccl_kv_transporter.py#L411-L415","tags":[]},{"url":"https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/nccl_kv_transporter.py#L437-L461","tags":[]},{"url":"https://www.vulncheck.com/advisories/lightllm-through-1.2.0-unauthenticated-remote-code-execution-via-nccl-pd-rpyc-control-channel","tags":[]}],"exploitRefs":[{"url":"https://github.com/ModelTC/LightLLM/issues/1590","tags":[]},{"url":"https://github.com/ModelTC/lightllm","tags":[]},{"url":"https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/kv_transporter.py#L20-L36","tags":[]},{"url":"https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/nccl_kv_transporter.py#L247-L249","tags":[]},{"url":"https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/nccl_kv_transporter.py#L411-L415","tags":[]},{"url":"https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/nccl_kv_transporter.py#L437-L461","tags":[]}],"hasPoc":true,"ai":{"summary":"LightLLM through 1.2.0 has a remote code execution vulnerability due to an unauthenticated RPyC control channel that deserializes attacker-supplied data, allowing arbitrary code execution with the service account privileges.","exploitability":"Exploitation is relatively straightforward given the unauthenticated nature of the RPyC control channel, and requires the --pd_trans_mode nccl flag to be set during service startup.","blast_radius":"If exploited, the vulnerability could lead to complete compromise of the LightLLM service, potentially allowing attackers to execute arbitrary code with the service account privileges.","remediation":"Disable the RPyC control channel or ensure that the --pd_trans_mode flag is not set to nccl during service startup. If disabling the feature is not feasible, upgrade to a version that addresses this vulnerability, such as LightLLM 1.2.1 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","auth-bypass","remote","service"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:50:58.285Z"}}