CVE-2026-90919EPSS p64.1%
CVE-2026-90919CVE-2026-90919
Description
LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads(). Attackers can reach the Config Server port and send a malicious serialized payload with a __reduce__ method to execute arbitrary code with Config Server process privileges.
Scoring
| CVSS | 9.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 1.09% probability of exploitation · percentile 64.1% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-23 |