Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
An unauthenticated attacker can remotely execute code on an LMCache server through a flaw in its multiprocess mode, which runs the cache as a standalone server reached by LLM workers over ZeroMQ. The critical vulnerability has no fixed version available, putting deployments that use this mode at risk.
Organizations running LMCache in multiprocess mode may face remote code execution without authentication, while no fixed version is available. Operators should assess exposure and mitigation options for affected cache servers.