Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-107204: lmcache lets anyone run code on your server

CVE-2026-107204 · published 3 days ago
Summary

The lmcache version up to 0.5.5 lets a remote user send a script to a specific web address and have it executed on the server. This means an attacker could run operating‑system commands with the same rights as the lmcache service, potentially taking control of the host. Update to a newer version or disable the /run_script endpoint until you can apply a fix.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
lmcache lmcache <= 0.5.5
Original advisory text
LMCache through 0.5.5 Unauthenticated RCE via /run_script Endpoint
LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected FastAPI app object, bypassing the guarded __import__, to import os and run operating system commands as the LMCache process.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen7 Oct 2026
Sources
CVE-2026-107204 · MITRE
Track software like this
Free during beta