A critical remote code execution vulnerability has been discovered in LMCache, a server used for LLM KV-caching with vLLM. The flaw, which exists in multiprocess mode, allows an unauthenticated attacker to execute code via ZeroMQ. As of now, no patched version of LMCache is available. AI
IMPACT This critical vulnerability in LMCache could expose AI inference systems using vLLM to security risks.
RANK_REASON Discovery of a vulnerability in a specific software component used in AI infrastructure.
Read on Mastodon — mastodon.social →
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →