LMCache 0.5.5 及之前版本存在一个未经验证的远程代码执行漏洞。攻击者可通过向 端点提交脚本,执行任意 Python 代码。通过注入到 FastAPI 应用对象中,攻击者能够绕过受保护的 机制,直接访问真实的内置模块(builtins),从而导入 模块并作为 LMCache 进程的用户执行操作系统命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105192 | 9.8 CRITICAL | LMCache Unauthenticated RCE in multiprocess mode via pickle deserialization |
| CVE-2026-107206 | 9.4 CRITICAL | LMCache through 0.5.5 Missing Authentication in MP HTTP Server Management API |
| CVE-2026-107205 | 8.6 HIGH | LMCache through 0.5.5 Missing Authentication in MP Coordinator Fleet Control API |
| CVE-2026-107207 | 7.2 HIGH | LMCache through 0.5.5 Missing Authentication in Frontend Node Catalog Allows SSRF Allowlis |
No comments yet