JFrog Flags Unpatched CVSS 9.8 RCE in LMCache vLLM Layer
TL;DR
- JFrog, the discoverer, confirmed a single unauthenticated ZMQ DEALER message triggers pickle.loads on attacker-controlled bytes before any type validation runs.
- Official LMCache container images run the process as root, making any successful RCE a full host takeover.
- Only distributed deployments with a routable --host binding are remotely exploitable; localhost-only setups are not at risk.
LMCache, the open-source KV-cache layer most commonly bolted onto vLLM inference servers, has an unauthenticated remote-code-execution flaw with a CVSS score of 9.8 and no fix as of October 7, The Hacker News reported. JFrog Security Research tracks it as CVE-2026-105192; versions from 0.3.9 onward, including the current 0.5.5 release and the 0.5.6rc3 candidate, remain vulnerable.
The bug lives in LMCache's multiprocess mode, which opens a ZeroMQ ROUTER socket on port 5555 by default. JFrog's advisory, credited to researcher Yuval Moravchick, notes the socket "lacks CURVE encryption, ZAP authentication, or message verification." Messages arrive as msgpack, and extension code 1 is wired to `DeviceIPCWrapper.Deserialize`, which calls `pickle.loads` on attacker-controlled bytes before any handler runs. One DEALER message executes arbitrary code as the LMCache process user, and "official container images run this process as root."
The blast radius depends on where the socket is bound. Default localhost binding limits exposure to a single node, but Moravchick flags that operators routinely set a routable address via the `--host` parameter when scaling vLLM across machines, which is the deployment shape that turns this into unauthenticated network RCE.
JFrog's interim guidance is to replace pickle with a safe serializer for extension code 1, add CURVE or HMAC-based auth on the transport, and firewall port 5555 off the network until a patched build ships. For scale context, our tracker has logged 445 AI infrastructure items in the last 90 days on the infrastructure beat, and LMCache sits squarely in the hot layer of that stack between vLLM and the GPU.
What others are reporting
-
JFrog Security Research Read →
Primary discoverer; includes working PoC code and confirms official containers run as root, elevating blast radius to full host compromise.
A single unauthenticated ZMQ DEALER message to the transport port therefore executes code as the user the LMCache process runs as.
-
TheHackerWire Read →
Adds Shodan dork 'port:5555 ZeroMQ' for live exposure enumeration; the only source confirming active reconnaissance is operationally feasible today.
A single crafted ZeroMQ message can grant an attacker root-level command execution on affected systems.
-
Forkast Read →
Frames the flaw as a systemic trust-through-defaults pattern also seen in Cisco NX-API, HPE ClearPass, and DB-GPT, situating it in a recurring infrastructure security failure mode.
A single, unauthenticated ZeroMQ DEALER message to port 5555 executes arbitrary code with the privileges of the LMCache process.
-
Cyber Press Read →
Focuses on the remediation gap: no patch exists yet, and the only current defense is a firewall rule blocking port 5555 from any routable interface.
An attacker who can reach that port can send a crafted ZeroMQ DEALER message without authenticating first.
-
ByteIota Read →
Connects the flaw to Pwn2Own Ireland 2026's new AI Infrastructure category, arguing self-hosted LLM stacks now face production-level adversarial scrutiny whether operators are ready or not.
The server unpacks messages before validating their type.
-
HOL Guard Read →
CVE tracker with structured inventory guidance and formal status tracking; useful for teams needing a versioned, machine-readable record of affected builds.
A single unauthenticated ZMQ message to the transport port executes code as the user the LMCache process runs as.
Originally reported by thehackernews.com
Read the original article →Original headline: Unpatched LMCache CVSS 9.8 RCE Flaw Hits vLLM Inference Stacks via Pickle Deserialization