Ethical Hacking News
LMCache Flaw Exposes Critical Vulnerability in Open-Source Software, Enabling Unauthenticated Attackers to Run Code Remotely
A critical vulnerability in LMCache has exposed a critical flaw that allows unauthenticated attackers to run code remotely. The vulnerability affects LMCache from version 0.3.9 through 0.5.5, as well as the 0.5.6 release candidates and the development branch. No fixed version exists, leaving users and organizations vulnerable to potential attacks. The vulnerability allows unauthenticated attackers to run code remotely, highlighting the importance of software security and the need for timely patching.
LMCache has a critical vulnerability (CVE-2026-105192) that allows unauthenticated attackers to run code remotely. The vulnerability is rooted in LMCache's multiprocess mode and affects LMCache versions 0.3.9 to 0.5.5, as well as release candidates and the development branch. The vulnerability can be exploited to gain elevated privileges on the server, potentially leading to malicious activities. Measures to prevent the server from being exposed to the internet, such as keeping the port local or on a trusted network, are advised. A related vulnerability in vLLM is already fixed, highlighting the importance of keeping software up-to-date. The vulnerability has significant implications for organizations relying on LMCache for their LLM servers.
A recent vulnerability in LMCache, an open-source software designed to speed up large language model (LLM) servers, has exposed a critical flaw that allows unauthenticated attackers to run code remotely. The vulnerability, tracked as CVE-2026-105192, affects LMCache from version 0.3.9 through 0.5.5, as well as the 0.5.6 release candidates and the development branch. Unfortunately, no fixed version exists, leaving users and organizations vulnerable to potential attacks.
The vulnerability is rooted in LMCache's multiprocess mode, where the cache server runs as a standalone server that LLM workers reach over the ZeroMQ messaging library. A single network message to that server can run commands as the user the LMCache process runs as. This means that an attacker can send a malicious message to the server, which will execute the command without any authentication checks. The server can be reached from another machine only when an operator sets it to listen on a routable address, rather than the localhost it uses by default.
The flaw was discovered by Yuval Moravchick of JFrog's security research team and has been assigned a severity score of 9.8 out of 10, categorizing it as a critical vulnerability. According to JFrog, the vulnerability arises from the fact that the ZeroMQ socket the multiprocess server opens for worker processes to register and share cached data has no authentication. One type of message is unpacked with pickle, a Python format that can carry code and run it as the data is decoded. The server unpacks it while still reading the message's arguments, before any check of the message's type, so a crafted message can run the sender's code.
The code runs with the privileges of the LMCache process. On the project's official container images, that process runs as root, according to JFrog. This means that an attacker can exploit the vulnerability to gain elevated privileges on the server, potentially leading to a range of malicious activities.
JFrog advises operators not to assign the multiprocess server a routable address and to keep its port on the local machine or on a trusted cluster network. A firewall that limits who can reach the port lowers the risk but does not remove it, because any host that can still open a connection can run code. However, this measure is not foolproof, as it relies on the attacker being aware of the port and its location.
In a separate report, a GitHub user claimed to have discovered unauthenticated access to cached data belonging to different tenants, as well as to several network services that execute commands without a login. These reports come from one account, rest on proof-of-concept claims, and have no CVE, no confirmation from the maintainers, and no fix. One points to a default LMCache that has since changed: an admin HTTP server that listened on every network interface in 0.5.5 listens only on the local host in the 0.5.6 release candidates.
Interestingly, a related flaw in vLLM is already fixed. Before version 0.30.0, released September 22, a single request carrying a malformed cache_salt value could crash the engine on deployments that use the LMCache multiprocess connector, a denial-of-service bug tracked as CVE-2026-105756. It is rated 6.5 and does not allow code execution. This highlights the importance of keeping software up-to-date and patching vulnerabilities in a timely manner.
The core mistake, handing data from an unauthenticated network socket to pickle, is the same one researchers found across other AI inference frameworks in November 2025, in a group of flaws they called ShadowMQ. Whether LMCache's code shares a common source with those projects has not been established.
The vulnerability has significant implications for organizations that rely on LMCache for their LLM servers. The lack of a fixed version means that users are left vulnerable to potential attacks, and the risk of unauthenticated attackers running code remotely is very real. As JFrog advises, it is crucial to take measures to prevent the server from being exposed to the internet, such as keeping its port on the local machine or on a trusted cluster network, and implementing a firewall that limits who can reach the port.
In conclusion, the LMCache vulnerability exposed in October 2026 is a critical reminder of the importance of software security and the need for timely patching. The vulnerability allows unauthenticated attackers to run code remotely, and the lack of a fixed version leaves users and organizations vulnerable to potential attacks. As the use of AI continues to grow, it is essential that we prioritize software security and take proactive measures to prevent vulnerabilities like this one.
Related Information:
https://www.ethicalhackingnews.com/articles/LMCache-Flaw-Exposes-Critical-Vulnerability-in-Open-Source-Software-Enabling-Unauthenticated-Attackers-to-Run-Code-Remotely-ehn.shtml
https://thehackernews.com/2026/10/unpatched-critical-lmcache-flaw-lets.html
https://nvd.nist.gov/vuln/detail/CVE-2026-105192
https://www.cvedetails.com/cve/CVE-2026-105192/
https://nvd.nist.gov/vuln/detail/CVE-2026-105756
https://www.cvedetails.com/cve/CVE-2026-105756/
Published: Wed Oct 7 12:33:41 2026 by llama3.2 3B Q4_K_M