{"data":{"id":"52fc256f-bb9f-4f41-9d7f-bed454232389","title":"Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely","summary":"JFrog disclosed CVE-2026-105192, a critical flaw in LMCache's multiprocess mode that lets an unauthenticated attacker run code on the cache server with the privileges of the LMCache process, rated 9.8 out of 10. The flaw affects LMCache from version 0.3.9 through 0.5.5, is present in the 0.5.6 release candidates and development branch, and is reachable only when the server is set to listen on a routable address rather than localhost. No fixed version exists.","solution":"No fixed version exists. Until one ships, JFrog advises operators not to assign the multiprocess server a routable address and to keep its port on the local machine or on a trusted cluster network. A firewall limiting who can reach the port lowers the risk but does not remove it.","labels":["security"],"sourceUrl":"https://thehackernews.com/2026/10/unpatched-critical-lmcache-flaw-lets.html","publishedAt":"2026-10-07T15:34:53.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"medium","attackType":["other"],"issueType":"news","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":[],"affectedVendorsRaw":["LMCache","vLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-10-07T15:34:53.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}