CVE-2026-96560: Modeltc Lightllm

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauthenticated RPyC control channel that deserializes attacker-supplied data. Attackers can send malicious pickled objects to the exposed RPyC ThreadedServer to execute arbitrary code with the privileges of the LightLLM service account.

Affected products

  • Modeltc Lightllm: up to and including 1.2.0

Published 2026-09-23. Last modified 2026-09-23.