Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
Security

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

The Hacker News · Oct 07, 2026

Back to News
Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
Security October 7, 2026

A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in LMCache's multiprocess mode, where the cache runs as a standalone server that LLM workers reach over the ZeroMQ messaging library. A single network

Read original on The Hacker News

Want to stay informed about new business solutions?

Follow us

Ready to build a better digital experience?

We create modern multilingual websites, integrate external services and automate content workflows for growing businesses.