CVE-2026-96560
9.8 CRITICALpublic exploit availablePublished 2026-09-23 · Updated 2026-09-23
AI risk analysis
- Summary
- LightLLM through 1.2.0 has a remote code execution vulnerability due to an unauthenticated RPyC control channel that deserializes attacker-supplied data, allowing arbitrary code execution with the service account privileges.
- Exploitability
- Exploitation is relatively straightforward given the unauthenticated nature of the RPyC control channel, and requires the --pd_trans_mode nccl flag to be set during service startup.
- Blast radius
- If exploited, the vulnerability could lead to complete compromise of the LightLLM service, potentially allowing attackers to execute arbitrary code with the service account privileges.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Disable the RPyC control channel or ensure that the --pd_trans_mode flag is not set to nccl during service startup. If disabling the feature is not feasible, upgrade to a version that addresses this vulnerability, such as LightLLM 1.2.1 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauthenticated RPyC control channel that deserializes attacker-supplied data. Attackers can send malicious pickled objects to the exposed RPyC ThreadedServer to execute arbitrary code with the privileges of the LightLLM service account.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-502
Public exploit & PoC references
- https://github.com/ModelTC/LightLLM/issues/1590
- https://github.com/ModelTC/lightllm
- https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/kv_transporter.py#L20-L36
- https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/nccl_kv_transporter.py#L247-L249
- https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/nccl_kv_transporter.py#L411-L415
- https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/nccl_kv_transporter.py#L437-L461
All references
- https://github.com/ModelTC/LightLLM/issues/1590
- https://github.com/ModelTC/lightllm
- https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/kv_transporter.py#L20-L36
- https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/nccl_kv_transporter.py#L247-L249
- https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/nccl_kv_transporter.py#L411-L415
- https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/nccl_kv_transporter.py#L437-L461
- https://www.vulncheck.com/advisories/lightllm-through-1.2.0-unauthenticated-remote-code-execution-via-nccl-pd-rpyc-control-channel
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-67827PoC
- CRITICALCVE-2025-66455PoC
- CRITICALCVE-2026-18163
- HIGHCVE-2026-67615PoC
- CRITICALCVE-2026-70416
- CRITICALCVE-2026-94301
- HIGHCVE-2026-96804
- CRITICALCVE-2017-20242
Related by shared AI tags and CWE weakness class. Browse the full archive.