CPE
LMCache versions up to 0.5.5 are vulnerable to unauthenticated remote code execution via the /run_script endpoint, allowing attackers to inject and execute arbitrary OS commands.