Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in LMCache that could allow unauthenticated attackers to execute arbitrary code on affected systems by sending specially crafted scripts to a specific endpoint. This could potentially lead to unauthorized system access and command execution.
- Unauthenticated remote code execution in LMCache.
- Critical severity, potential for unauthorized system access.
- Confirm relevance and assess exposure to LMCache.
Attack Path
How an attacker could exploit the issue
An attacker can target the LMCache caching engine by sending specially crafted scripts to the `/run_script` endpoint. This endpoint, exposed via FastAPI, does not require authentication, allowing any remote attacker to submit Python code. The vulnerability permits the attacker to bypass import restrictions and execute arbitrary operating system commands as the LMCache process, potentially leading to full system compromise.
- No authentication is required.
- Attacker posts scripts to `/run_script`.
- Remote code execution.
Live Threat
Current exploitation, exposure, and threat context
An unauthenticated remote code execution vulnerability in LMCache could allow attackers to run operating system commands as the LMCache process. This could happen when the `/run_script` endpoint is accessible over the network and attackers can leverage a mechanism to recover built-in Python functions.
- System commands could be executed.
- Via unauthenticated network requests.
- Compromise of the LMCache process.
Operational Fix
Recommended remediation, mitigation, and detection steps
This unauthenticated remote code execution vulnerability in LMCache could allow attackers to run commands on your systems. Infrastructure and platform teams are likely responsible for managing LMCache deployments. The first practical step is to identify all instances of LMCache, determine their network exposure and business criticality, and then assign ownership to an accountable team for risk-based remediation.
- Own the LMCache exposure.
- Verify LMCache network reachability.
- Plan risk-based remediation.