CVE-2026-90919 | ModelTC LightLLM up to 1.2.0 visual_register WebSocket endpoint pickle.loads deserialization

SecurityVulns

A vulnerability was found in ModelTC LightLLM up to 1.2.0. It has been classified as critical. This vulnerability affects the function pickle.loads of the component visual_register WebSocket endpoint. Performing a manipulation results in deserialization.

This vulnerability is reported as CVE-2026-90919. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More