Critical flaw in LMCache KV cache server allows remote code execution as root

JFrog disclosed a critical vulnerability (CVE-2026-105192) in LMCache, a caching layer for large language models. The flaw, rated 9.8 out of 10, allows unauthenticated remote code execution via a ZeroMQ socket with no authentication. Versions 0.3.9 through 0.5.5 and development branches are affected, with no fixed version currently available. The vulnerability exists because the server deserializes messages using Python's pickle library before validating them. Official container images run the process as root, granting full system privileges to attackers who can reach the exposed socket.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in