CVE-2026-26220
Critical · CVSS 9.3LightLLM — Unauthenticated WebSocket pickle deserialization RCE
- CVSS
- 9.3
- nvd
- EPSS
- 0.66%
- 47th pct
- KEV
- No
- Class
- oss containerizable
- CWE-502
Description
LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) disaggregation mode. The PD master node exposes WebSocket endpoints that receive binary frames and pass the data directly to pickle.loads() without authentication or validation. A remote attacker who can reach the PD master can send a crafted payload to achieve arbitrary code execution.
Search profile — drives PoC discovery
Symbols pickle.loadsapi_http.pyPD master nodeWebSocketprefill-decode disaggregationbinary framespd_masterL310L331
Keywords CVE-2026-26220LightLLM pickle RCELightLLM deserializationLightLLM PD disaggregation exploitLightLLM WebSocket pickleLightLLM unauthenticated RCEModelTC LightLLM CVELightLLM api_http pickle.loadschocapikk lightllm
Versions: <= 1.1.0
References
- https://chocapikk.com/posts/2026/lightllm-pickle-rce/
- https://github.com/ModelTC/LightLLM/issues/1213
- https://github.com/ModelTC/lightllm/blob/a27dfc88c2144ed51a6e160b6fbe20aad66c8fe0/lightllm/server/api_http.py#L310
- https://github.com/ModelTC/lightllm/blob/a27dfc88c2144ed51a6e160b6fbe20aad66c8fe0/lightllm/server/api_http.py#L331
- https://lightllm-en.readthedocs.io/en/latest/index.html
- https://www.vulncheck.com/advisories/lightllm-pd-mode-unsafe-deserialization-rce
Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z