AI Weekly Malaysia

Back to items Summaries

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

ID
32837
Status
summarized
Published
07 Oct 2026, 11:34 PM
Fetched
08 Oct 2026, 12:50 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/10/unpatched-critical-lmcache-flaw-lets.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.5
Created
08 Oct 2026, 12:51 AM
Tags
Audience
developersai_ml_learners

What happened

JFrog disclosed CVE-2026-105192 on October 7, a 9.8-severity flaw in LMCache, the open-source cache that accelerates LLM servers such as vLLM. In LMCache's multiprocess mode the cache runs as a standalone server that LLM workers reach over an unauthenticated ZeroMQ socket; one crafted message is unpacked with pickle before the server checks the message type, so it executes attacker code as the LMCache process — which runs as root on the project's official container images. It affects versions 0.3.9 (October 2025) through 0.5.5, plus 0.5.6 release candidates and the development branch, and no fixed version exists; JFrog's advice until a patch ships is to not give the multiprocess server a routable address.

Why it matters

Exposure comes down to one startup setting: the server binds localhost by default, but LMCache's own example Kubernetes deployment starts it listening on every network interface, so teams that copied that manifest for multi-node cache sharing are running an unauthenticated root RCE right now. If you self-host vLLM or any LLM worker with LMCache's multiprocess server, check the bind address today and pin it to localhost or a private interface until a patched release lands — LMCache inside a single vLLM process does not open the port, so that setup is unaffected. There is no Malaysian-specific detail in this report, but for local teams running self-hosted inference on cloud or Kubernetes, this is an immediate config check rather than a wait-for-patch item.

Discussion angle

The insecure-by-default example: LMCache's own Kubernetes manifest binds the cache to every interface, and the process runs as root in the official images — worth walking through how many of our self-hosted inference stacks were set up by copy-pasting a vendor's sample YAML, and what a minimal safe default (localhost bind, non-root user, auth on the ZeroMQ socket) would have looked like here.

Top