Threat Intelligence

Critical Flaw in LMCache AI Software Lets Attackers Run Code Without a Password, and No Fix Exists Yet

The Hacker News · 8 Oct 2026
Key Takeaway If you run LMCache in multiprocess mode, check now that its server is not listening on a routable address, and restrict network access to it until a fixed version is released.

A critical vulnerability in LMCache, open-source software that speeds up large language model servers such as vLLM, allows an attacker to run commands on the cache server without logging in. JFrog disclosed the flaw, tracked as CVE-2026-105192, on October 7 and rated it 9.8 out of 10. It affects versions 0.3.9 through 0.5.5, the latest stable release, as well as the 0.5.6 release candidates and the development branch. No fixed version is available.

The problem sits in LMCache's multiprocess mode, where the cache runs as a standalone server and AI workers connect over the ZeroMQ messaging library. The server's socket has no authentication. One type of message is decoded using pickle, a Python format that can carry code and run it during decoding, and this happens before the message type is checked. A single crafted network message can therefore run commands with the privileges of the LMCache process. JFrog says that process runs as root on the project's official container images.

Exposure depends on one setting. By default the server listens only on the local machine, so other hosts cannot reach it. It becomes reachable when an operator sets a routable address, as multi-node deployments do. LMCache's own example Kubernetes deployment listens on every network interface. Running LMCache inside a single vLLM process does not open the port at all.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.