The Hacker News

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in LMCache's multiprocess mode, where the cache runs as a standalone server that LLM workers reach over the ZeroMQ messaging library. A single network

By The Hacker News

1 min read
Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
AI-generated illustration

Got news to share with the events industry?

Submit a press release or story tip and reach thousands of event professionals.

Get in touch→

More in Cybersecurity, Cryptography & Digital Trust

Related Insights