Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-107204: lmcache lets anyone run code on your server
CVE-2026-107204 · published 3 days ago
Summary
The lmcache version up to 0.5.5 lets a remote user send a script to a specific web address and have it executed on the server. This means an attacker could run operating‑system commands with the same rights as the lmcache service, potentially taking control of the host. Update to a newer version or disable the /run_script endpoint until you can apply a fix.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| lmcache | lmcache | <= 0.5.5 |
Original advisory text
LMCache through 0.5.5 Unauthenticated RCE via /run_script Endpoint
LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected FastAPI app object, bypassing the guarded __import__, to import os and run operating system commands as the LMCache process.
References
- https://github.com/LMCache/LMCache
- https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/internal_api_server/co...
- https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/multiprocess/http_apis...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-1072... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-107204 Vendor Advisory
- https://www.vulncheck.com/advisories/lmcache-through-0.5.5-unauthenticated-rce-v...
- https://github.com/LMCache/LMCache/issues/5510
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.3
Critical
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen7 Oct 2026
Track software like this
Free during beta