CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-107204 — LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerab...

·Source: NIST NVD

Updated:

Executive Summary

LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected FastAPI app object, bypassing the guarded __import__, to import os and run operating system commands as the LMCache process.

Analysis

LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected FastAPI app object, bypassing the guarded __import__, to import os and run operating system commands as the LMCache process. CVSS Score: 9.8. Published: 2026-10-07T16:17:45.113.

Indicators of Compromise (1)

CVE (1)
CVE-2026-107204
Source Attribution

Originally published by NIST NVD on Oct 7, 2026. Verified by: NIST.

Related Threats

CRITICALVulnerability

Making the Case to the Board for Post-Quantum Readiness

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/making-case-to-board-for-post-quantum-readiness-image_small-1-a-33036.jpg" align=right hspace=4><b>Frame Quantum Risk Around Business Exposure, Timelines and Staged Investment</b><br>CIOs seeking board support for post-quantum readiness should skip the physics lesson. The stronger case connects vulnerable cryptography to critical

Bank Info Security
MEDIUMVulnerability

China Could Coerce Taiwan by Hacking Comms, Think Tank Warns

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/war-game-tests-taiwans-telecom-backups-against-china-image_small-3-a-33034.jpg" align=right hspace=4><b>War Game Pits Taiwan's Telecom Sector Against China</b><br>A concerted Chinese attempt to take over neighboring Taiwan is more likely to involve "cyber-enabled economic warfare" rather than outright invasion, warns a Washington,

Bank Info Security
MEDIUMVulnerability

Oracle Health's Cerner EHR Breach Figure Soars to 20 Million

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/oracle-healths-cerner-ehr-server-hack-soars-to-20m-affected-image_small-10-a-33033.jpg" align=right hspace=4><b>Vendor Has Updated Breach Reports to Several States Including Texas</b><br>The number of patients affected in a 2025 hacking incident involving health data managed by electronic health record vendor Cerner has soared to

Bank Info Security