CyberSecurity News
Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
AI summary
A critical vulnerability has been discovered in LMCache, an open-source software used to accelerate large language model servers. This flaw allows unauthenticated attackers to execute code remotely on the cache server without needing to log in. The vulnerability is specifically located in LMCache's multiprocess mode, where the cache operates as a standalone server accessed by LLM workers via the ZeroMQ messaging library. An attacker can exploit this flaw over a single network connection. Currently, there is no fixed version of LMCache available to address this issue.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

