CVE-2026-96560: Modeltc Lightllm
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauthenticated RPyC control channel that deserializes attacker-supplied data. Attackers can send malicious pickled objects to the exposed RPyC ThreadedServer to execute arbitrary code with the privileges of the LightLLM service account.
Affected products
- Modeltc Lightllm: up to and including 1.2.0
Published 2026-09-23. Last modified 2026-09-23.