Skip to content
LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Config Server Pickle ...

LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Config Server Pickle ...

Vulncheck • September 14, 2026

LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Config Server Pickle Deserialization

CWE-502 Deserialization of Untrusted Data

visual_websocket_endpoint pickle.loads sink at v1.2.0

Ready to get Started?

Vulnerability Prioritization Prioritize vulnerabilities that matter based on the threat landscape and defer vulnerabilities that don't.

Early Warning System Real-time alerting of changes in the vulnerability landscape so that you can take action before the attacks start.

Extracted Entities