Canadian Cyber Security Journal
SOCIAL:
Filed under: Featured, TechTalk

Unpatched LMCache Flaw CVE-2026-105192 Allows Remote Code Execution: What Canadian AI Teams Must Check

What Happened

JFrog researcher Yuval Moravchick disclosed CVE-2026-105192, a critical remote code execution flaw in LMCache. LMCache is open-source software built to accelerate large language model servers such as vLLM. The Hacker News reports JFrog scored the flaw 9.8 out of 10. No fixed version exists.

The flaw affects versions 0.3.9 through 0.5.5 in multiprocess mode. In this mode, the cache runs as a standalone server and workers reach it over ZeroMQ. The socket requires no authentication. The server deserializes one message type with pickle before it checks the message type. One crafted message runs commands as the LMCache process user. On the project’s official container images, this user is root.

Exposure depends on configuration. The server listens on localhost by default. The example Kubernetes DaemonSet binds to all interfaces, so teams who copy it expose the port. No exploitation has been reported, and LMCache has not published a security advisory.

Why This Matters for Canadian Organizations

Canadian banks, health networks, and public sector teams are building private AI services to keep data inside the country. Many run vLLM on Kubernetes and add a cache layer for speed. A copied example manifest is how this flaw reaches production. Root access on an inference node gives an attacker model weights, prompts, and any customer data held in the cache.

Prompts carry personal information in many deployments. A breach of this data triggers PIPEDA breach reporting and, in Quebec, Law 25 duties. Federally regulated institutions also answer to OSFI Guideline B-13, which covers third-party and open-source components.

What to Do

Find every LMCache deployment, including pilot clusters. Check whether multiprocess mode is on. Confirm the port is bound to localhost or a trusted cluster network. Apply network policies so only the worker pods reach it. Rebuild images to run as a non-root user. Watch the JFrog advisory and the LMCache repository for a fixed release. Review our TechTalk coverage and daily briefs for related alerts.

Enjoy this article? Don’t forget to share.