[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fI4yruSJirl6YI5tfnNtYxb1QVy03KpwkEWoYtBF7TpI":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"865ca172-78e1-4b10-864e-89b176a65b00","unpatched-lmcache-flaw-enables-unauthenticated-remote-code-execution","35ccd5ec-2472-4390-b92e-1a3f2ebfddc7","Unpatched LMCache Flaw Enables Unauthenticated Remote Code Execution","A critical vulnerability in LMCache (CVE-2026-105192) exposes servers to unauthenticated remote code execution due to the unsafe use of Python's pickle deserialization module over an unauthenticated ZeroMQ socket. Pickle deserialization is a well-known dangerous pattern that can execute arbitrary code during the unpickling process, and exposing it without authentication is a fundamental design flaw. Compounding the risk, certain deployment examples and misconfigurations can expose the vulnerable socket beyond the default local scope, potentially granting attackers root-level access. This case highlights the danger of insecure defaults in open-source AI\u002FML tooling, a rapidly expanding attack surface that is often under-scrutinized in security reviews.","**Immediate actions:**\n- Upgrade LMCache to a patched version beyond 0.5.6 as soon as it becomes available, or temporarily disable ZeroMQ socket exposure until a fix is applied.\n- Audit all LMCache deployment configurations to confirm ZeroMQ sockets are not exposed to untrusted networks or the public internet.\n- Apply network firewall rules to restrict access to LMCache ZeroMQ ports to only trusted internal hosts.\n\n**Long-term improvements:**\n- Replace or wrap any use of Python's pickle module with safe serialization alternatives (e.g., JSON, MessagePack, or protobuf) in all internal tooling and dependencies.\n- Integrate software composition analysis (SCA) tools into CI\u002FCD pipelines to automatically flag unsafe deserialization patterns and known vulnerable dependencies.\n- Establish a formal review process for open-source AI\u002FML tools before deployment, including security assessments of serialization mechanisms and network exposure.\n\n**Detection measures:**\n- Deploy network monitoring to alert on unexpected connections to ZeroMQ or high-numbered ports associated with LMCache services.\n- Enable process-level logging on LMCache hosts to detect anomalous child processes that may indicate successful code execution.\n- Subscribe to CVE feeds and vendor advisories specifically covering your AI\u002FML toolchain to ensure rapid awareness of newly disclosed vulnerabilities.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 7: Continuous Vulnerability Management","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 12: Network Infrastructure Management","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 CM-6: Configuration Settings","NIST SP 800-53 AC-3: Access Enforcement","NIST SP 800-53 SC-7: Boundary Protection","NIST SP 800-53 SA-9: External System Services (Supply Chain)","OWASP A08:2021 – Software and Data Integrity Failures (Insecure Deserialization)","NIST CSF ID.AM-2: Software platforms and applications inventoried","NIST CSF PR.IP-1: Baseline configuration established and maintained","published","2026-10-07T18:21:31.734605+00:00","2026-10-07T18:21:31.402+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Funpatched-critical-lmcache-flaw-lets.html","unpatched-critical-lmcache-flaw-lets-unauthenticated-attackers-run-code-remotely-4d160a","Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":39,"name":40,"slug":41,"description":42,"color":43},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":45,"name":46,"slug":47,"description":48,"color":49},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]