Cyber Security News

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process deployments by exploiting unsafe Python pickle deserialization.

This flaw is tracked as CVE-2026-105192 and has a CVSS score of 9.8. JFrog published an advisory and a public proof-of-concept exploit on October 7, 2026, stating that no fixed release was available as of that date.

Yuval Moravchick of the JFrog Security Research Team discovered the vulnerability, and it is documented under advisory JFSA-2026-001694382.

The vulnerable decoding path first appeared in version 0.3.9 and remains present in version 0.5.5, as well as in all release candidates up to 0.5.6rc3 and the development branch reviewed on October 7.

LMCache RCE Vulnerability

LMCache’s multiprocess mode, also known as distributed mode, opens a ZeroMQ ROUTER socket that allows worker processes to register and share key-value cache blocks.

Although this transport is designed for sibling LMCache processes, it lacks authentication (e.g., CURVE, ZAP, or password protection), leaving reachable instances vulnerable to untrusted messages.

By default, this transport uses localhost. Operators can enable connectivity between nodes by configuring a routable address using the `–host` option.

JFrog emphasizes that the severe 9.8 score applies only to this network-reachable configuration, not to the default single-host deployment, which is inaccessible from other machines. LMCache running solely within a vLLM process does not open the affected port.

Incoming messages use MessagePack, with extension code 1 associated with DeviceIPCWrapper. During decoding, the extension hook in `lmcache/v1/multiprocess/custom_types.py` forwards the embedded data to `DeviceIPCWrapper.Deserialize` in `lmcache/v1/platform/base/ipc_wrapper.py`. This function invokes `pickle.loads`, allowing attacker-controlled serialized objects to trigger code execution.

Importantly, deserialization occurs while the server processes REGISTER_KV_CACHE arguments, before the request handler is executed. As a result, any argument checks or handler errors that follow cannot prevent code that has already been executed during decoding.

JFrog’s public demonstration sends a crafted multipart message through a ZeroMQ DEALER socket to the transport’s default port, 5555. The cache payload includes a MessagePack extension containing a malicious pickle object that executes an operating system command during reconstruction.

The demonstration writes the output of the `id` command to `/tmp/zmq_pwn`, confirming execution under the LMCache process account. Official container images run this process as root, confirming root execution inside the container, rather than demonstrating an escape to the underlying host.

After execution, the server logs a type error because the handler receives the command’s return value instead of the expected wrapper object. This error occurs too late to prevent exploitation.

JFrog recommends replacing pickle-based network deserialization with a safe serialization format and authenticating the ZeroMQ transport using methods like CURVE or per-message HMAC verification. Routable binding should be disallowed unless authentication is configured.

Until these changes are implemented, operators should avoid using routable `–host` settings, keep localhost binding whenever possible, and restrict required cluster access with firewall rules. While network isolation can limit exposure, it does not fix the flaw; any system that can connect to the vulnerable transport can still execute code with the privileges of the LMCache process.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

1 hour ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

2 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

3 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

4 hours ago

wolfSSH Patches 5 Security Vulnerabilities, Including Critical SSH Authentication Bypass

wolfSSL has released wolfSSH version 1.6.0, which addresses five security vulnerabilities, including a critical flaw…

4 hours ago

Critical Gitea Vulnerabilities Allow Attackers to Bypass Authentication and Execute Code

Gitea has released version 28.0.0, addressing 20 vulnerabilities related to authentication bypass, unauthorized workflow execution,…

4 hours ago