DEV Community

Mark0
Mark0

Posted on

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

A critical unauthenticated remote code execution (RCE) vulnerability, tracked as CVE-2026-105192, has been discovered in LMCache, an open-source software used to accelerate large language model (LLM) servers such as vLLM. The flaw resides in the multiprocess mode, where the server uses the ZeroMQ messaging library. Due to insecure pickle deserialization of network messages, an attacker can execute arbitrary commands with the privileges of the LMCache process, which often runs as root in official container images.

There is currently no patched version available for LMCache, which affects versions 0.3.9 through 0.5.5. Security researchers at JFrog, who disclosed the flaw with a severity rating of 9.8, recommend that operators avoid assigning routable addresses to the multiprocess server and restrict access via firewalls or trusted cluster networks until a fix is released.


Read Full Article

Top comments (0)