CriticalVulnerabilityLLM-specific
LMCache is vulnerable to Unauthenticated Remote Code Execution via Pickle Deserialization on the Multiprocess ZMQ Transport
- Published
- Record updated
Summary
CVE-2026-105192, rated CVSS 9.8 critical, affects lmcache versions up to and including 0.3.9 in multiprocess (distributed) mode. The ZeroMQ ROUTER transport has no authentication, and a single crafted REGISTER_KV_CACHE frame reaches pickle.loads through DeviceIPCWrapper.Deserialize during argument decoding, executing commands as the LMCache process user, which is root in official container images. The score applies when the transport is bound to a routable address rather than the default localhost.
Mitigation
No fixed version has been published as of 2026-10-07. The source advises stopping network data from being passed to pickle, replacing the serializer behind msgpack extension code 1 with a safe format, and not calling pickle.loads on data that a
Topics
Related items
- LowAnthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsSimilar attack · The Hacker News
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading