{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/lightllm--1.2.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:lightllm:lightllm:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-90919"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["LightLLM (\u003c= 1.2.0)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["LightLLM"],"content_html":"\u003cp\u003eLightLLM versions through 1.2.0 contain a critical remote code execution (RCE) vulnerability in the Config Server component. The vulnerability resides in the /visual_register WebSocket endpoint, which fails to implement any authentication mechanisms. The application insecurely handles client-provided frames by passing the first frame directly to the Python pickle.loads() function. An unauthenticated attacker capable of reaching the Config Server network port can send a maliciously crafted, serialized pickle payload containing a \u003cstrong\u003ereduce\u003c/strong\u003e method. Successful exploitation allows the attacker to execute arbitrary code within the context of the Config Server process. Given the nature of pickle-based deserialization vulnerabilities, this flaw poses a high risk to environment integrity, as it grants full execution capabilities to remote, unauthenticated parties.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify reachable Config Server endpoints.\u003c/li\u003e\n\u003cli\u003eAttacker establishes a WebSocket connection to the /visual_register endpoint on the target server.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious Python object payload using the pickle module's \u003cstrong\u003ereduce\u003c/strong\u003e method.\u003c/li\u003e\n\u003cli\u003eAttacker sends the serialized binary data as the first frame over the established WebSocket.\u003c/li\u003e\n\u003cli\u003eThe Config Server component receives the payload and passes the data to pickle.loads().\u003c/li\u003e\n\u003cli\u003eThe Python interpreter deserializes the malicious object, triggering the execution of the embedded instructions.\u003c/li\u003e\n\u003cli\u003eAttacker achieves arbitrary code execution with the permissions of the underlying service account.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-90919 allows for complete compromise of the affected Config Server process. In enterprise environments, this could lead to lateral movement, data exfiltration, or deployment of further persistence mechanisms. There is currently no mitigation or patch specified; users should restrict network access to the Config Server port.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize network segmentation to ensure the LightLLM Config Server port is not accessible from untrusted or external networks. Monitor application logs for unexpected WebSocket connection attempts to the /visual_register URI.\u003c/p\u003e\n","date_modified":"2026-09-18T22:08:02Z","date_published":"2026-09-14T13:33:20Z","id":"https://feed.craftedsignal.io/briefs/2026-09-lightllm-rce/","summary":"LightLLM versions 1.2.0 and earlier are vulnerable to unauthenticated remote code execution via the Config Server's /visual_register WebSocket endpoint due to insecure pickle deserialization.","title":"Remote Code Execution in LightLLM Config Server via Insecure Deserialization","url":"https://feed.craftedsignal.io/briefs/2026-09-lightllm-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - LightLLM (\u003c= 1.2.0)","version":"https://jsonfeed.org/version/1.1"}