PoC Released for Critical LMCache Flaw Enabling Unauthenticated Remote Code Execution
JFrog released a proof-of-concept for unauthenticated remote code execution in LMCache, tracked as CVE-2026-105192, with no patch.
JFrog Security Research published a proof-of-concept for CVE-2026-105192, a CVSS 9.8 flaw in LMCache multiprocess mode that allows unauthenticated remote code execution. The ZeroMQ service, default port 5555, decodes MessagePack and calls pickle.loads before validation, so one crafted DEALER message can run code as the LMCache process. Builds from 0.3.9 through PyPI 0.5.5 and 0.5.6 release candidates through 0.5.6rc3 were still unpatched on October 7. The issue is remotely reachable when the listener is bound to an address such as 0.0.0.0; a localhost-only setup is not exposed the same way.