Junglewise Threat Intelligence

CVE-2026-26220: ModelTC LightLLM remote code execution in PD WebSocket endpoints

CVE-2026-26220 · Severity: info · CVSS 9.3 · Published 2026-02-17

Technologies: ModelTC LightLLM. Vendors: ModelTC.

Executive brief

LightLLM is a framework used to deploy and run large language models (LLMs). A security flaw in its distributed processing mode allows an unauthenticated attacker to remotely execute arbitrary commands on the server. This could lead to a total system takeover, theft of sensitive AI models, or access to customer data processed by the engine.

Technical details

A critical remote code execution vulnerability exists in LightLLM's PD (prefill-decode) disaggregation mode due to the use of the unsafe 'pickle.loads()' function on untrusted data. The PD master node exposes WebSocket endpoints, specifically '/pd_register' and '/kv_move_status', which accept binary frames and deserialize them without any authentication or validation. Because the application explicitly prevents binding to localhost in this mode, these endpoints are network-exposed by design. An attacker can send a crafted pickle payload to these endpoints to achieve arbitrary code execution with the privileges of the application process. As of the advisory date, the issue remains unpatched in version 1.1.0.

Affected products

  • ModelTC LightLLM <= 1.1.0

Timeline

  • 2025-03: other: Similar deserialization issue reported via ZMQ (#784)
  • 2026-02-11: disclosed: Vulnerability discovered and confirmed by researcher
  • 2026-02-12: other: CVE-2026-26220 assigned
  • 2026-02-15: advisory: Public disclosure via GitHub issue #1213
  • 2026-02-17: other: NVD publication date

References

Related threats