Junglewise Threat Intelligence

CVE-2026-93839: LightLLM authentication bypass in /pd_register WebSocket endpoint

CVE-2026-93839 · Severity: critical · CVSS 9.8 · Published 2026-09-18

Technologies: ModelTC LightLLM. Vendors: ModelTC.

Executive brief

LightLLM is a Python-based framework for serving large language models. An unauthenticated attacker can register a rogue compute node via the /pd_register WebSocket endpoint, allowing them to intercept all user prompts (including sensitive data like API keys and personal information), cause complete service outages, or use the service to make requests to internal networks. The attack requires only network access to the endpoint and no valid credentials.

Technical details

The /pd_register WebSocket endpoint accepts connections without authentication and accepts node registration JSON without validating that the declared client address belongs to the attacker. The vulnerability permits silent replacement of legitimate nodes in the routing pool via list-filter logic, enabling prompt interception and request hijacking. Additionally, the unvalidated client_ip_port is interpolated into health-check URLs, enabling SSRF attacks against internal addresses.

Affected products

  • ModelTC LightLLM through 1.2.0

Timeline

  • 2026-09-18: disclosed

References

Related threats