CVE-2026-90919

LOW

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Deep dive

Full discourse2 posts
  • Cybersecurity News DE@cybsecuritynews

    #schwachstellen CVE-2026-90919: Kritische RCE-Lücke in LightLLM bis Version 1.2.0 #cve202690919 #lightllm #pickle #remotecodeexecution #websocket https://cybersecurity-news.de/cve-2026-90919-lightllm-rce-bis-1-2-0

    0000014
    12 followersView on X
  • Upwind Security MDR@UpwindMDR

    🚨Critical - LightLLM Config Server WebSocket Pickle RCE (CVE-2026-90919) LightLLM Config Server /visual_register WebSocket passes the first client frame directly into pickle.loads(). Unauthenticated attackers with network access to the Config Server port can send a malicious pickle (__reduce__) to execute arbitrary code as the Config Server process. Instances not exposing the Config Server port externally are not impacted. 👉Affected: LightLLM <= 1.2.0

    0000068
    303 followersView on X

Explore more