ModelTC has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 9.8 (critical), with 2 rated critical.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.8
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
2
Total CVEs
2
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-90919Critical· 9.8LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads()66CVE-2026-93839Critical· 9.8LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation54
ModelTC vulnerabilities
CVEs affecting ModelTC, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-93839Critical· 9.8LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation
LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. At…
▾ MidnightModelTC · LightLLMEPSS 0.60%via NVD
CVE-2026-90919Critical· 9.8PoCLightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads()
LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads(). Attackers can reach the Confi…
▾ AbyssalModelTC · LightLLMEPSS 1.0%via NVD