External risk intelligence

LightLLM Authentication Bypass in WebSocket Registration Endpoint

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-93839

The vulnerability affects a WebSocket endpoint used for node registration in LightLLM. While these components often reside in internal clusters or private networks for distributed resource coordination, the service is network-accessible. Public internet exposure is not the standard deployment pattern for node registration APIs, but potential misconfiguration could expose the endpoint.

Missing Authentication

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in LightLLM software that could allow unauthorized access to register new nodes. This could potentially expose user prompts, disrupt service, or enable malicious requests to internal systems. The main concern is confirming relevance and exposure.

  • Unauthenticated attackers can register nodes in LightLLM.
  • Critical to understand if our systems use this software.
  • Prioritize verifying if this software is in use.

Attack Path

How an attacker could exploit the issue

An attacker can bypass authentication to register new nodes in the system through a WebSocket endpoint. This allows them to intercept sensitive information, disrupt service by replacing legitimate nodes, or manipulate the system into making requests to internal network addresses.

  • Unauthenticated network access required.
  • Register arbitrary nodes via WebSocket.
  • Disclose prompts, deny service, or redirect requests.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to register arbitrary nodes with the LightLLM system without proper validation. This could lead to unauthorized access to user prompts, service disruption, or the ability to direct the system to make requests to internal network addresses.

  • Unauthenticated node registration.
  • Bypassing peer address validation.
  • Disclosure of user prompts and internal requests.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in LightLLM's WebSocket registration endpoint requires immediate attention from teams managing AI infrastructure or custom LLM deployments. The first step is to identify all instances of LightLLM, determine their exposure and criticality, and confirm responsible ownership for remediation, which may involve platform or application teams.

  • Identify LightLLM instances and exposure.
  • Confirm business-criticality and accountable owner.
  • Plan risk-based remediation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is LightLLM?

LightLLM is an open-source software framework designed for high-performance serving of Large Language Models. It provides the infrastructure needed to manage inference workloads, enabling developers to deploy LLMs efficiently by coordinating various computing nodes and resources.

What is the nature of the CVE-2026-93839 vulnerability?

This vulnerability is classified as a missing authentication weakness (CWE-306). It specifically affects the WebSocket endpoint used for node registration in LightLLM. Because the software fails to verify credentials or peer addresses, an attacker can impersonate a legitimate node to gain unauthorized access to the system's internal communication flows.

How does an attacker trigger this vulnerability?

An attacker triggers this flaw by sending a specifically crafted JSON message to the /pd_register WebSocket endpoint. It is important to note that sending standard, legitimate traffic to the server does not cause this issue; the system only becomes compromised when it accepts and processes these malicious, unauthenticated registration requests.

Is my LightLLM deployment at risk?

Halo Surface Signal indicates that while these registration endpoints are typically kept within private networks or internal clusters, they may still be reachable depending on your network configuration. You should evaluate whether your LightLLM instances are unintentionally exposed to broader network segments, as any network-level access could potentially allow an unauthorized party to interact with the vulnerable endpoint.

What should I do first to address this?

Your first step is to conduct an inventory to locate all active LightLLM deployments within your infrastructure. Once identified, confirm which teams own these services and assess their current network accessibility. Prioritize limiting access to the registration endpoints and consult the software maintainers for available updates to secure the WebSocket communication path.

References