A critical vulnerability in LMCache, opensource software that speeds up large language model LLM servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in LMCache's multiprocess mode, where the cache runs as a standalone server that LLM workers reach over the ZeroMQ messaging library. A single network.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity