Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

Image: The Hacker News
ad slot · in-content video 16:9
Coverage
More coverage
- A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in LMCache's multiprocess mode, where the cache runs as a…