JFrog disclosed a critical flaw on Wednesday in LMCache, a cache used with vLLM. A single unsigned network message runs attacker code, and official images run as root. No patch exists yet, a working exploit is public, and only multi-node setups listen.