CVE-2026-107204: Schwachstellen-Eintrag (NVD)
LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected FastAPI app object, bypassing the guarded __import__, to import os and run operating system commands as the LMCache process.
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-23 | 2026-10-07 |
|---|---|---|
| ≥90 % | 491 | 344 |
| ≥50 % | 1475 | 1071 |
| ≥10 % | 0 | 3 |
| <10 % | 0 | 549 |
CVE-2026-107204 | LMCache up to 0.5.5 os command injection (EUVD-2026-94383)
A vulnerability was found in LMCache up to 0.5.5. It has been rated as critical. The impacted element is an unknown function. The manipulation leads to os command injection. This vulnerability is uniquely identified as CVE-2026-107204. The
Noch keine Analyse zu CVE-2026-107204
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.