CRITICAL 9.3 NVD

CVE-2026-93839

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to internal network addresses.

References

Published: 2026-09-18 · Source: NVD · Feed updated: 2026-09-18
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-18 via NVD.

Risk Timeline

CVE Disclosed2026-09-18 · -1 days ago

Remediation Resources

vulnfeed aggregates 14357 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.