Skip to content
CriticalVulnerabilityLLM-specific

LMCache is vulnerable to Unauthenticated Remote Code Execution via Pickle Deserialization on the Multiprocess ZMQ Transport

Published
Record updated
View JSON

Summary

CVE-2026-105192, rated CVSS 9.8 critical, affects lmcache versions up to and including 0.3.9 in multiprocess (distributed) mode. The ZeroMQ ROUTER transport has no authentication, and a single crafted REGISTER_KV_CACHE frame reaches pickle.loads through DeviceIPCWrapper.Deserialize during argument decoding, executing commands as the LMCache process user, which is root in official container images. The score applies when the transport is bound to a routable address rather than the default localhost.

Mitigation

No fixed version has been published as of 2026-10-07. The source advises stopping network data from being passed to pickle, replacing the serializer behind msgpack extension code 1 with a safe format, and not calling pickle.loads on data that a