Known Vulnerabilities for LightLLM by ModelTC
Listed below are 10 of the newest known vulnerabilities associated with "LightLLM" by "ModelTC".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-103395 json | LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserial... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-103270 json | LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Una... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-103243 json | LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal endpoints, allowing unauthenticated... | Not Provided | 2026-09-30 | 2026-10-02 |
| CVE-2026-103042 json | LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mo... | Not Provided | 2026-09-29 | 2026-10-02 |
| CVE-2026-103041 json | LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enable... | Not Provided | 2026-09-29 | 2026-09-30 |
| CVE-2026-103040 json | LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enab... | Not Provided | 2026-09-29 | 2026-09-30 |
| CVE-2026-96560 json | LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-93839 json | LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows una... | Not Provided | 2026-09-18 | 2026-09-22 |
| CVE-2026-90919 json | LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-26220 json | LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) disagg... | Not Provided | 2026-02-17 | 2026-07-14 |