CVE-2026-26220EPSS p75.9%
CVE-2026-26220CVE-2026-26220
Description
LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) disaggregation mode. The PD master node exposes WebSocket endpoints that receive binary frames and pass the data directly to pickle.loads() without authentication or validation. A remote attacker who can reach the PD master can send a crafted payload to achieve arbitrary code execution.
Scoring
| EPSS | 1.66% probability of exploitation · percentile 75.9% · 2026-10-06T12:00:23Z |
| Last modified | 2026-07-14 |