{"id":"CVE-2026-107204","title":"LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint","summary":"LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the inj…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-306"],"vendor":"LMCache","product":"LMCache","affected":["LMCache <= 0.5.5"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T17:16:53.657","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107204","references":[{"url":"https://github.com/LMCache/LMCache","label":"disclosure@vulncheck.com"},{"url":"https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/internal_api_server/common/run_script_api.py#L54-L76","label":"disclosure@vulncheck.com"},{"url":"https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/multiprocess/http_apis/common_api.py#L41-L46","label":"disclosure@vulncheck.com"},{"url":"https://github.com/LMCache/LMCache/issues/5510","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/lmcache-through-0.5.5-unauthenticated-rce-via-run-script-endpoint","label":"disclosure@vulncheck.com"},{"url":"https://github.com/LMCache/LMCache/issues/5510","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"total","timestamp":"2026-10-07T17:08:57.542279Z"},"ingestedAt":"2026-10-07T16:38:22.224Z","slug":"CVE-2026-107204","body":"## Overview\n\nLMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected FastAPI app object, bypassing the guarded __import__, to import os and run operating system commands as the LMCache process.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":217636,"id":"CVE-2026-107204","ts":1791394908068,"field":"exploit_available","old":"false","new":"true"}]}