hacker-news · Crawled Oct 7, 2026

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

1 CVEs
Read original article ↗

AI Summary

A critical unpatched vulnerability, CVE-2026-105192, exists in LMCache versions 0.3.9 through 0.5.5 and affects release candidates and the development branch. The flaw resides in the multiprocess mode where the cache server uses ZeroMQ without authentication and deserializes untrusted data using Python's pickle module, allowing unauthenticated remote code execution. Attackers can execute arbitrary code with the privileges of the LMCache process, which runs as root in official container images. JFrog, who discovered the flaw, warns operators to avoid exposing the multiprocess server to routable networks until a fix is available.

AI-extracted · verify before operational use

Extracted Entities 1 found

MITRE ATT&CK TTPs 1 techniques