CVE-2026-103270
HIGH
NVD
CVSS Score
7.5
Severity
HIGH
Published
Sep 30, 2026
Vendor
unknown
Description
LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, and /init_weights_update_group to disrupt inference operations and wedge workers on deployments started with --enable_rl.
References
- https://github.com/ModelTC/LightLLM
- https://github.com/ModelTC/LightLLM/issues/1609
- https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/api_http.py#L505-L507
- https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/api_http_rl.py#L51-L139
- https://www.vulncheck.com/advisories/lightllm-through-1.2.0-missing-authentication-on-rl-control-routes