CyberRota Analysis
AI-GeneratedLightLLM versions up to 1.2.0 are vulnerable due to the lack of authentication checks on their public HTTP API, allowing unauthenticated attackers to access critical endpoints such as /pause_generation and /abort_request. This vulnerability can lead to disruption of inference operations and potential denial of service by wedging workers in deployments configured with reinforcement learning. Organizations using this software should prioritize patching to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, and /init_weights_update_group to disrupt inference operations and wedge workers on deployments started with --enable_rl.