Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-93839: LightLLM lets unauthenticated users add nodes via WebSocket

CVE-2026-93839 · published 10 days ago
Summary

The LightLLM service (version 1.2.0 and earlier) does not check who can use the /pd_register WebSocket endpoint, so anyone can create fake nodes. This can expose user prompts, disrupt service by replacing real nodes, or cause the system to contact internal network addresses. Apply the latest update or restrict access to the endpoint to trusted users.

Original advisory text
LightLLM through 1.2.0 Missing Authentication in PD Master /pd_register WebSocket Endpoint
LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to internal network addresses.
Severity
9.9 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published18 Sep 2026
Updated27 Sep 2026
First seen18 Sep 2026
Sources
Track software like this
Free during beta