CVE-2026-107204
Received Received - Intake

Unauthenticated Remote Code Execution in LMCache

Vulnerability report for CVE-2026-107204, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: VulnCheck

Description

LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected FastAPI app object, bypassing the guarded __import__, to import os and run operating system commands as the LMCache process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
LMCache LMCache 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-107204 is an unauthenticated remote code execution (RCE) vulnerability in LMCache through version 0.5.5. It allows attackers to execute arbitrary Python code by sending scripts to the /run_script endpoint. The vulnerability arises because the sandbox uses the FastAPI app object, enabling bypass of restrictions to import the 'os' module and run operating system commands with the LMCache process privileges.

Detection Guidance
  • Check if LMCache's internal API server is running on port 6999 by running: netstat -tulnp | grep 6999 or ss -tulnp | grep 6999
  • Inspect network traffic for POST requests to /run_script endpoint using tools like tcpdump or Wireshark
  • Review LMCache logs for unauthorized script executions or unexpected imports
  • Verify if the internal_api_server_enabled flag is set to true in LMCache configuration
Impact Analysis

This vulnerability allows remote attackers to execute arbitrary code on the server running LMCache. If exploited, it can lead to full system compromise, including unauthorized access to sensitive data, installation of malware, or disruption of services. The impact depends on the privileges of the LMCache process.

Compliance Impact

This vulnerability can lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. It may result in data breaches, unauthorized processing, or loss of data integrity, potentially leading to legal penalties, fines, or reputational damage for organizations handling regulated data.

Mitigation Strategies
  • Disable the internal API server by setting internal_api_server_enabled to false in configuration
  • Block external access to port 6999 using firewall rules if the API server must remain enabled
  • Upgrade to a patched version of LMCache if available (no patch mentioned for 0.5.5)
  • Monitor for suspicious activity or unauthorized access attempts to the /run_script endpoint

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107204. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart