CVE-2026-107204: fallo crítico en LMCache
LMCache through 0.5.5 Unauthenticated RCE via /run_script Endpoint
Publicada el
25Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 9.3
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected FastAPI app object, bypassing the guarded __import__, to import os and run operating system commands as the LMCache process.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
LMCache · LMCacheCVEs relacionadas — LMCache
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-105192CRITICALLMCache Unauthenticated RCE in multiprocess mode via pickle deserializationEPSS 0.7%CVE-2026-107207MEDIUMLMCache through 0.5.5 Missing Authentication in Frontend Node Catalog Allows SSRF Allowlist BypassEPSS —CVE-2026-107206HIGHLMCache through 0.5.5 Missing Authentication in MP HTTP Server Management APIEPSS —CVE-2026-107205HIGHLMCache through 0.5.5 Missing Authentication in MP Coordinator Fleet Control APIEPSS —
Referencias
https://github.com/LMCache/LMCachehttps://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/internal_api_server/common/run_script_api.py#L54-L76https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/multiprocess/http_apis/common_api.py#L41-L46https://github.com/LMCache/LMCache/issues/5510https://www.vulncheck.com/advisories/lmcache-through-0.5.5-unauthenticated-rce-via-run-script-endpoint