Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

The Hacker News - Oct 7, 2026

A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in LMCache's multiprocess mode, where the cache runs as a standalone server that LLM workers reach over the ZeroMQ messaging library. A single network

Read full article

More News

About Us
Logo

In-Depth Science delivers comprehensive and compelling news and analysis on everything science and technology, seven days a week in a reader-friendly format.

Contact us: sales[at]indepthscience.com

Copyright © 2015 - 2026 In-Depth Science. All Rights Reserved.