GHSA-xgvf-x9rh-chj9CriticalCVSS 9.8

LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows...

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected FastAPI app object, bypassing the guarded import, to import os and run operating system commands as the LMCache process.

🔗 References (7)