PT-2026-95638 · Lightllm · Lightllm
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LightLLM versions prior to 1.2.1
Description
An authentication bypass exists in the
/pd register WebSocket endpoint. Unauthenticated attackers can register arbitrary nodes by providing crafted JSON, as the system fails to perform peer address validation. This can lead to the disclosure of full user prompts routed to the attacker's socket, denial of service by replacing legitimate nodes, or Server-Side Request Forgery (SSRF), allowing the PD Master to issue requests to internal network addresses.Recommendations
Update LightLLM to a version later than 1.2.0.
Restrict access to the
/pd register WebSocket endpoint to minimize the risk of exploitation.Exploit
Fix
DoS
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lightllm