WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity SINGLE SOURCE

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

Padlock and key on a table in front of dark server racksAI illustration
WORLDTECH illustration · AI-generated (Canva)

What happened

A critical vulnerability in LMCache, open-source (published so anyone may read, use and change the code) software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in LMCache's multiprocess mode, where the cache runs as a standalone server that LLM workers reach over the ZeroMQ messaging library.

Sources & evidence