Skip to content
Threat Feed
critical advisory

Unauthenticated Remote Code Execution in LMCache

LMCache versions up to 0.5.5 are vulnerable to unauthenticated remote code execution via the /run_script endpoint, allowing attackers to inject and execute arbitrary OS commands.

CVE search metadata

CVE search record: CVE-2026-107204. Severity: critical. CVSS: 9.8. KEV: no. Product: LMCache (<= 0.5.5). Brief: Unauthenticated Remote Code Execution in LMCache. Brief link: https://feed.craftedsignal.io/briefs/2026-10-lmcache-rce/

What's new

  • 1. added detection rule: Detect CVE-2026-107207 Exploitation - POST Request to /api/proxies Oct 7, 17:04 via nvd

LMCache versions up to 0.5.5 contain a critical unauthenticated remote code execution (RCE) vulnerability. An attacker can exploit this by sending a crafted HTTP POST request to the /run_script endpoint. The application fails to properly secure the environment, allowing the attacker to interact with the FastAPI app object. By leveraging this object, an attacker can bypass Python's guarded import restrictions to retrieve real built-in functions, load the 'os' module, and subsequently execute arbitrary operating system commands with the privileges of the LMCache process. This vulnerability poses a severe risk, as it allows for full compromise of the underlying host system without requiring prior authentication. Organizations utilizing LMCache should prioritize patching to version 0.5.6 or higher or restrict network access to the management interface.

Attack Chain

  1. Attacker performs network reconnaissance to identify exposed LMCache instances.
  2. Attacker sends a malicious HTTP POST request to the target's /run_script endpoint.
  3. The LMCache application accepts the input and processes the provided script.
  4. Attacker utilizes the FastAPI app object to access and recover restricted Python built-in functions.
  5. Attacker bypasses guarded import mechanisms to import the 'os' library.
  6. Attacker invokes system functions within the Python script to execute arbitrary OS commands.
  7. OS commands run with the privileges of the LMCache service process.
  8. Attacker gains persistence or exfiltrates data from the compromised host.

Impact

Successful exploitation of CVE-2026-107204 results in full remote code execution on the server running LMCache. An attacker gains the ability to execute arbitrary commands, potentially leading to complete system takeover, data exfiltration, or deployment of further payloads. Given the critical 9.8 CVSS score, this vulnerability is highly attractive for opportunistic exploitation against internet-facing infrastructure.

Recommendation

  • Upgrade LMCache to version 0.5.6 or later immediately to address CVE-2026-107204.
  • Apply network segmentation to restrict access to the LMCache /run_script endpoint to known, trusted management IPs.
  • Deploy the provided Sigma rule to monitor for suspicious POST requests to the /run_script path.
  • Enable web server access logs to audit all requests directed at the LMCache API.

Immediate actions

Upgrade LMCache to version 0.5.6 or later.

IT Operations 24h

Threat Hunt

Search web logs for POST requests to /run_script from unauthorized IP ranges.

T1190 high high confidence hunt now

Data: Web server access logs

Mitigations

Restrict access to the management endpoint /run_script via firewall or WAF.

immediate IT Operations

CVE-2026-107204

Detection coverage 2

Detects CVE-2026-107204 Exploitation - Unauthorized POST to /run_script

critical

Detects unauthorized attempts to access the /run_script endpoint which is associated with RCE exploitation in LMCache.

sigma tactics: execution, initial_access techniques: T1059.006, T1190 sources: webserver

Detect CVE-2026-107207 Exploitation - POST Request to /api/proxies

high

Detects potential SSRF exploitation attempts where an unauthenticated actor attempts to register arbitrary hosts via the /api/proxies endpoint.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →