VYPR
Critical severity9.8NVD Advisory· Published Sep 14, 2026· Updated Sep 14, 2026

CVE-2026-90919

CVE-2026-90919

Description

LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads(). Attackers can reach the Config Server port and send a malicious serialized payload with a __reduce__ method to execute arbitrary code with Config Server process privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • ModelTC/Lightllmreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=1.2.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.