PoC Released for Critical LMCache Flaw Enabling Unauthenticated Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A proof-of-concept (PoC) exploit has been released for a critical vulnerability in LMCache that can allow unauthenticated remote code execution on exposed distributed deployments.

Tracked as CVE-2026-105192, the flaw has a CVSS score of 9.8 and affects LMCache versions beginning with 0.3.9. As of October 7, JFrog Security Research reported no fixed release.

The vulnerability, identified by Yuval Moravchick of the JFrog Security Research Team, exists in LMCache’s multiprocess mode, also known as distributed mode.

This deployment setup uses a ZeroMQ (ZMQ) service so that multiple worker processes can register and share key-value cache blocks. The issue becomes serious when administrators configure the service to listen on a routable network address for multi-node use.

LMCache is commonly used alongside large language model inference systems to improve performance by sharing and reusing cached data.

However, JFrog found that its multiprocess ZMQ transport accepts messages without authentication. The service does not use ZeroMQ CURVE security, ZAP authentication, passwords, or message-level verification. This leaves the transport open to anyone who can reach the exposed port.

The vulnerable service uses MessagePack (msgpack) to decode data sent over the ZMQ connection. During this process, LMCache handles a custom MessagePack extension through the DeviceIPCWrapper.Deserialize function. That function calls Python’s pickle. loads, which is unsafe when it processes data received from an untrusted source.

Python pickle data can contain instructions that run code while it decodes. In this case, a remote user can send a crafted ZMQ message containing a malicious pickle object.

LMCache processes that object before it validates the message or passes it to the intended handler. As a result, the supplied code can run under the permissions of the LMCache process.

PoC Released for Critical LMCache Flaw

JFrog’s PoC shows that a single unauthenticated ZeroMQ DEALER message sent to the default service port, 5555, can trigger code execution.

Unauthenticated RCE in LMCache (source : JFrogSecurity )
Unauthenticated RCE in LMCache (source : JFrogSecurity )

The proof-of-concept writes command output to a local file to demonstrate successful execution. In official LMCache container images, the process reportedly runs as root, which means successful exploitation could give an intruder root-level control of the affected container.

The issue is most dangerous in multi-node deployments where LMCache is started with the –host option set to a routable address such as 0.0.0.0. In that setup, remote systems can connect to the ZMQ transport.

A standard single-host setup that keeps the listener bound to localhost is not reachable from other machines and is not exposed in the same way.

JFrog said the unsafe decode path was introduced in LMCache version 0.3.9. It remains present in the latest PyPI release, version 0.5.5, as well as version 0.5.6 release candidates through 0.5.6rc3 and the development branch reviewed on October 7.

The advisory states that no patched LMCache version had been released at the time of disclosure. The flaw shows a familiar risk for AI and machine-learning environments: exposed internal services using Python pickle for network data.

Cyber Security News previously reported on related pickle-based remote code execution risks affecting Meta’s Llama Stack, where insecure ZeroMQ communications also allowed crafted serialized objects to run code on vulnerable servers.

Until LMCache releases a fix, administrators should avoid exposing the multiprocess service publicly, keep it on localhost where possible, or restrict access to trusted networks using firewalls and segmentation.

The long-term fix requires removing pickle.loads from unauthenticated network data handling. JFrog recommended replacing the serializer used in the MessagePack extension with a safe data format and adding strong transport authentication, such as ZeroMQ CURVE or a message authentication code. LMCache should also prevent routable network binding unless authentication is explicitly enabled.

Organizations running LMCache in distributed AI inference environments should immediately review exposed ZMQ listeners, check whether port 5555 is reachable across their network, and run LMCache services with the least possible privileges.

The critical nature of CVE-2026-105192 comes from the combination of unauthenticated network access, unsafe pickle decoding, and the possibility of root execution in default container deployments.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post PoC Released for Critical LMCache Flaw Enabling Unauthenticated Remote Code Execution appeared first on Cyber Security News.