Unauthorized Code Execution in LMCache Distributed Mode by LMCache
CVE-2026-105192

9.8CRITICAL

Key Information:

Vendor

Lmcache

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-105192?

The LMCache distributed mode introduces a vulnerability where an unauthenticated ZeroMQ ROUTER allows worker processes to register and share key-value cache blocks. This may lead to code execution as the user running the LMCache process, potentially with elevated privileges if running as root. It involves a msgpack extension that is improperly deserialized using pickle, allowing malicious actors to send specially crafted messages to exploit this flaw.

Affected Version(s)

LMCache 0.3.9

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuval Moravchick
JFrog Security Research
.