MediumNewsLLM-specific
Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
- Published
- Record updated
Summary
JFrog disclosed CVE-2026-105192, a critical flaw in LMCache's multiprocess mode that lets an unauthenticated attacker run code on the cache server with the privileges of the LMCache process, rated 9.8 out of 10. The flaw affects LMCache from version 0.3.9 through 0.5.5, is present in the 0.5.6 release candidates and development branch, and is reachable only when the server is set to listen on a routable address rather than localhost. No fixed version exists.
Mitigation
No fixed version exists. Until one ships, JFrog advises operators not to assign the multiprocess server a routable address and to keep its port on the local machine or on a trusted cluster network. A firewall limiting who can reach the port lowers the risk but does not remove it.
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database