CVE-2026-93839
LightLLM through 1.2.0 Missing Authentication in PD Master /pd_register WebSocket Endpoint
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to internal network addresses.
| CWE | CWE-306 |
| Vendor | modeltc |
| Product | lightllm |
| Published | Sep 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for modeltc lightllm
Be the first to know when new critical vulnerabilities affecting modeltc lightllm are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
ModelTC / LightLLM
0 โค 1.2.0
References
github.com: https://github.com/ModelTC/LightLLM/issues/1576 github.com: https://github.com/ModelTC/LightLLM github.com: https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/api_http_pd.py#L26-L36 github.com: https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/httpserver_for_pd_master/manager.py#L714-L749 github.com: https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/httpserver_for_pd_master/manager.py#L691-L698 github.com: https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/api_http.py#L198-L205 vulncheck.com: https://www.vulncheck.com/advisories/lightllm-through-1.2.0-missing-authentication-in-pd-master-pd-register-websocket-endpoint
Credits
๐ Jiapeng Li ๐ Mingkai Yu ๐ Jiajia Liu