PT-2026-107562 · Lmcache · Lmcache

·

CVE-2026-107204

·

Publicado

2026-10-07

·

Atualizado

2026-10-07

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run script endpoint. Attackers can recover real builtins through the injected FastAPI app object, bypassing the guarded import , to import os and run operating system commands as the LMCache process.

Exploit

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-107204

Produtos afetados

Lmcache