External risk intelligence

LMCache Unauthenticated Remote Code Execution via Run Script Endpoint.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-107204

LMCache is designed as a caching engine that exposes a FastAPI-based network interface for remote interaction. The vulnerability resides in an API endpoint (/run_script) intended for interaction. Given that such services are frequently deployed to provide remote caching functionality for distributed applications or API-driven workflows, it is commonly reachable in network-accessible deployment patterns.

Missing Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in LMCache that could allow unauthenticated attackers to execute arbitrary code on affected systems by sending specially crafted scripts to a specific endpoint. This could potentially lead to unauthorized system access and command execution.

  • Unauthenticated remote code execution in LMCache.
  • Critical severity, potential for unauthorized system access.
  • Confirm relevance and assess exposure to LMCache.

Attack Path

How an attacker could exploit the issue

An attacker can target the LMCache caching engine by sending specially crafted scripts to the `/run_script` endpoint. This endpoint, exposed via FastAPI, does not require authentication, allowing any remote attacker to submit Python code. The vulnerability permits the attacker to bypass import restrictions and execute arbitrary operating system commands as the LMCache process, potentially leading to full system compromise.

  • No authentication is required.
  • Attacker posts scripts to `/run_script`.
  • Remote code execution.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated remote code execution vulnerability in LMCache could allow attackers to run operating system commands as the LMCache process. This could happen when the `/run_script` endpoint is accessible over the network and attackers can leverage a mechanism to recover built-in Python functions.

  • System commands could be executed.
  • Via unauthenticated network requests.
  • Compromise of the LMCache process.

Operational Fix

Recommended remediation, mitigation, and detection steps

This unauthenticated remote code execution vulnerability in LMCache could allow attackers to run commands on your systems. Infrastructure and platform teams are likely responsible for managing LMCache deployments. The first practical step is to identify all instances of LMCache, determine their network exposure and business criticality, and then assign ownership to an accountable team for risk-based remediation.

  • Own the LMCache exposure.
  • Verify LMCache network reachability.
  • Plan risk-based remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is LMCache?

LMCache is a caching engine designed to improve the performance of distributed applications and API-driven workflows by managing data storage. It utilizes a FastAPI-based network interface to handle remote interactions, allowing systems to efficiently cache and retrieve information within larger software architectures.

What does CWE-306 mean for CVE-2026-107204?

CWE-306 refers to Missing Authentication for Critical Function. In the context of this vulnerability, it means the software performs a sensitive action—specifically executing Python code—without verifying the identity of the user. Because this protection is missing, an attacker can directly interact with the system to run unauthorized commands.

How is this vulnerability triggered?

An attacker triggers the vulnerability by submitting a script to the /run_script endpoint of an affected LMCache instance. The system processes this request without requiring authentication, allowing the attacker to bypass import safeguards and execute operating system commands. Simply accessing the service without sending these specific malicious payloads does not trigger the code execution.

Is my LMCache instance at risk?

Your risk depends on your network configuration. According to Halo Surface Signal, LMCache services are frequently deployed in ways that are reachable over the network to provide remote caching functionality. If your instance is internet-facing or accessible to unauthorized users on your internal network, it is exposed to this remote code execution threat.

What should I do first to address CVE-2026-107204?

Start by identifying every instance of LMCache running in your environment. Once you have a complete inventory, verify whether these instances are reachable over your network. Finally, assign responsibility to the appropriate team to manage the risk and implement necessary security controls or updates to restrict access to the affected endpoint.

References