
🚨Critical - LightLLM KV-transfer Worker RPyC Pickle RCE (CVE-2026-96560) LightLLM KV-transfer worker started with --pd_trans_mode nccl exposes an unauthenticated RPyC ThreadedServer control channel. Attackers can send malicious pickled objects that get deserialized, achieving remote code execution as the LightLLM service account. Other pd_trans_mode values are not affected. 👉Affected: LightLLM <= 1.2.0
