Critical severity9.8NVD Advisory· Published Oct 7, 2026· Updated Oct 7, 2026
CVE-2026-107204
CVE-2026-107204
Description
LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected FastAPI app object, bypassing the guarded __import__, to import os and run operating system commands as the LMCache process.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/internal_api_server/common/run_script_api.pynvd
- github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/multiprocess/http_apis/common_api.pynvd
- github.com/LMCache/LMCache/issues/5510nvd
- www.vulncheck.com/advisories/lmcache-through-0.5.5-unauthenticated-rce-via-run-script-endpointnvd
News mentions
0No linked articles in our index yet.