Impact
The vulnerability arises from an improper access control flaw in the MountSegment Request Processing component of kvcache-ai mooncake. Manipulating input to the ScopedSegmentAccess::MountSegment function allows an attacker to gain unauthorized access to protected segments, thereby compromising data confidentiality and potentially altering system state. The attack can be launched remotely, and a public exploit technique has already been released, indicating a real risk to systems that have not mitigated the issue.
Affected Systems
kvcache-ai mooncake versions up to and including 0.3.12, 0.3.13.post1, and 0.3.14-rc1 are affected. The flaw is present in the segment.cpp file within the MountSegment Request Processing module.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability presents a moderate severity rating. The EPSS score is not available and the version is not listed in the CISA KEV catalog, but the availability of a public exploit and the remote nature of the attack suggest a tangible risk. Systems with exposed MountSegment interfaces should consider the risk high enough to trigger mitigation procedures.
OpenCVE Enrichment