
Four new LMCache flaws, all affecting versions through 0.5.5: CVE-2026-107204 (9.8): unauthenticated RCE via /run_script CVE-2026-107206 (9.4): management API without auth, leaks credentials CVE-2026-107205 (8.6): fleet API without auth CVE-2026-107207 (7.2): SSRF allowlist bypass VulnTracker recommends keeping LMCache services off the internet until patched. http://vulntracker.io/cves/CVE-2026-107204 #LMCache #AISecurity #RCE #CVE
