Executive brief
LightLLM's Config Server is a control-plane service that coordinates deployment and configuration of machine-learning inference workloads. The /visual_register WebSocket endpoint accepts unauthenticated connections and deserializes untrusted data using Python's pickle module, allowing remote attackers to execute arbitrary code with Config Server process privileges. This compromises the entire cluster orchestration layer.
Technical details
The vulnerability is an unsafe deserialization flaw (CWE-502) in the /visual_register WebSocket endpoint of LightLLM's Config Server (lightllm/server/config_server/api_http.py, line 83). The handler accepts WebSocket connections without authentication, immediately calls pickle.loads() on the first client-supplied binary frame, and stores the deserialized object in a registry. Because pickle can execute arbitrary Python code during reconstruction via __reduce__ methods and other mechanisms, an attacker with network access to the Config Server port can send a malicious serialized object to achieve remote code execution with the service process privileges. No authentication or validation occurs before deserialization, and the VIT_Obj type annotation provides no runtime security enforcement. The issue affects LightLLM through version 1.2.0.
Affected products
- ModelTC LightLLM through 1.2.0
Timeline
- 2026-09-14: disclosed
- 2026-09-14: advisory