CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107204

CRITICALCVSS 9.8NVD feed

Published 7 October 2026 · tracked since 8 October 2026

Description

LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected FastAPI app object, bypassing the guarded __import__, to

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-107204 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107204

CRITICALCVSS 9.8NVD feed

Published 7 October 2026 · tracked since 8 October 2026

Description

LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected FastAPI app object, bypassing the guarded __import__, to

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]