Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
A critical vulnerability in LMCache, open-source software that accelerates large language model servers such as vLLM, allows an attacker to run code on the cache server without logging in. The flaw affects LMCache's multiprocess mode, where the cache runs as a standalone server reached over ZeroMQ, and no fixed version is available.
- The flaw affects LMCache's multiprocess mode with a standalone cache server
- LLM workers connect to the cache via the ZeroMQ messaging library
- Attackers need no authentication to execute code remotely
- No patched version of LMCache is available yet
Read next
Security