# Critical LMCache Vulnerability Exposes Servers to Remote Code Execution

*Published October 9, 2026*
*Source: [https://thehackernews.com/2026/10/unpatched-critical-lmcache-flaw-lets.html](https://thehackernews.com/2026/10/unpatched-critical-lmcache-flaw-lets.html)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/critical-lmcache-vulnerability-exposes-servers-to-remote-code-execution) or [see plans](https://www.sec-news.ai/pricing).*

## Article

A severe vulnerability in LMCache, an open-source software used to speed up large language model servers such as vLLM, has been discovered. This flaw allows attackers to execute code on the cache server without authentication. The vulnerability is present in the multiprocess mode of LMCache, where the server communicates over the ZeroMQ messaging library. A single network message can trigger commands to run as the LMCache process user. This issue becomes critical when the cache server is configured to listen on a routable address instead of the default localhost setting. JFrog identified this flaw and disclosed it on October 7, assigning it a severity score of 9.8 out of 10, indicating a critical level of risk. The vulnerability, tracked as CVE-2026-105192, affects versions from 0.3.9, released in October 2025, to the latest stable release 0.5.5, as well as 0.5.6 release candidates and the development branch. As of now, no patched version is available. The default configuration restricts server access to the local machine, but altering this setting allows exposure to remote attacks. JFrog advises operators to avoid setting the multiprocess server to a routable address and to restrict port access to local machines or trusted networks. Firewalls can reduce the risk by controlling access to the port, although they cannot eliminate it entirely since any host that can connect can potentially execute code. Currently, LMCache has not released a security advisory regarding this flaw, leaving operators without a clear way to determine if their servers have been compromised. Additionally, reports of other security concerns related to LMCache have surfaced, although these remain unconfirmed and lack official fixes. A related flaw in vLLM, tracked as CVE-2026-105756, was fixed in version 0.30.0, released on September 22, addressing a denial-of-service vulnerability. The underlying issue stems from processing data from an unauthenticated network socket with the Python 'pickle' format, a mistake previously found in other AI inference frameworks.
