External risk intelligence

LightLLM Config Server Pickle Deserialization Remote Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-90919

The vulnerability affects a Config Server WebSocket endpoint. While this service is designed for internal infrastructure coordination and management rather than public-facing traffic, it is network-reachable, and specific deployment environments may inadvertently expose such configuration services to broader networks.

Deserialization

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability allows unauthenticated attackers to execute arbitrary code on affected systems by sending a malicious payload to a configuration server. The issue stems from how the system deserializes data, potentially giving attackers control over the compromised server process. The main concern is confirming relevance and exposure given the affected technology.

  • Unauthenticated code execution risk exists.
  • Critical vulnerability in configuration service.
  • Confirm relevance and exposure of this service.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by reaching the Config Server over the network and sending a specially crafted message to the `/visual_register` WebSocket endpoint. This endpoint processes the message's initial data without proper validation, passing it directly to a deserialization function that can be manipulated to execute arbitrary commands on the server. This could allow an attacker to gain control of the server with the same permissions as the running process.

  • Unauthenticated network access to the Config Server.
  • Sending a malicious serialized payload via WebSocket.
  • Arbitrary code execution with process privileges.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an unauthenticated attacker could execute arbitrary code on the Config Server. This could occur when the Config Server's WebSocket endpoint receives a malicious serialized payload, potentially leading to unauthorized access and control with the privileges of the Config Server process.

  • Config Server process code.
  • Malicious payload sent over WebSocket.
  • Arbitrary code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in the LightLLM Config Server requires immediate attention from teams managing AI infrastructure and application security. The primary concern is an unauthenticated remote code execution flaw via the `pickle.loads()` function, which allows attackers to send malicious serialized payloads. The first practical step is to identify all instances of the affected technology, determine their network exposure and business criticality, locate the accountable owner, and then plan remediation based on the assessed risk.

  • Ownership: Platform and application security teams.
  • Verify: Network reachability and business criticality.
  • Action: Prioritize and plan secure configuration management.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is LightLLM?

LightLLM is a software framework designed for high-performance large language model serving. It includes components like the Config Server, which helps manage and coordinate infrastructure settings for AI workloads. Users typically deploy it to streamline the inference process for LLMs, making it a foundational part of an AI-driven application stack.

How does CVE-2026-90919 work?

This vulnerability is an instance of CWE-502, which is the insecure deserialization of untrusted data. The Config Server uses the Python 'pickle' module to process incoming data from a WebSocket endpoint. Because it does not validate this data first, an attacker can send a specially crafted serialized object that forces the server to execute malicious commands during the deserialization process.

What triggers this vulnerability?

An attacker triggers this by sending a malicious payload to the /visual_register WebSocket endpoint on the LightLLM Config Server. Simply having the software installed is not enough; the attacker must be able to establish a network connection to that specific Config Server port. Traffic that does not target this WebSocket endpoint or that is blocked by network access controls will not trigger the exploit.

Is my instance affected by this?

According to Halo Surface Signal, this vulnerability impacts the Config Server, which is typically intended for internal infrastructure management. While not usually designed for public internet traffic, your instance may be at risk if the Config Server port is network-reachable or inadvertently exposed to broader networks. You should check your network architecture to see if this management service is accessible beyond your trusted internal segments.

How do I respond to CVE-2026-90919?

First, identify all systems in your environment running LightLLM versions up to 1.2.0. Assess the network reachability of the Config Server to determine which instances are exposed. Coordinate with your platform and security teams to restrict access to the affected port as a temporary measure while you prepare to implement the necessary secure configuration management or software updates provided by the project maintainers.

References