Critical LMCache flaw allows remote code execution
π‘οΈ A critical vulnerability in LMCache lets unauthenticated attackers execute code on the cache server when it is configured to listen on a routable address. The flaw resides in multiprocess mode where ZeroMQ messages are unpickled before type checks, enabling crafted messages to run with the LMCache process's privileges. JFrog disclosed the issue (CVE-2026-105192) on October 7 and rated it 9.8/10; no patched release is available, and operators are advised to keep the server bound to localhost or restrict network access.
