The application’s API address does not fully describe who can call the server or where model execution occurs. Model switching can also introduce cold-load latency and memory pressure.

Which deployment does this concern?

Authentication is optional by default. Enabling network serving makes the API reachable beyond localhost. With LM Link, a localhost API request can be served by a model on a linked remote machine.

Applies to: Configuration-dependent behaviour. Native API-token authentication is documented for LM Studio 0.4.0 or newer; this case does not identify a vulnerable version range.

Vendor controls and evaluation

The vendor provides native API tokens and permissions, recommends authentication for network binds, documents LM Link routing, and exposes idle TTL and Auto-Evict controls.

Configuration to validate: Enable required authentication and scoped token permissions for shared access; approve bind addresses and remote devices; configure model residency intentionally.

What clients can learn

Verify effective server settings, token permissions and execution location. Measure first-load and repeated-request behaviour under the model lifecycle settings your application actually uses.

Keep an endpoint inventory, the effective configuration and the running artifact together. A configuration or model change should trigger a review of the boundary it changes. Assign an owner to the evidence and to any required action.

Questions for your provider

  • Do requests without a valid token fail on the deployed API?
  • Which inference, model-management and tool permissions does each token have?
  • Does LM Link resolve the model to an approved device?
  • How do JIT loading, explicit loads, idle TTL and Auto-Evict affect latency and memory?

Use the inference guide and evaluation worksheet to record the answer in your deployment context.

Technical detail: source scope and identifiers

This is documented configuration behaviour, not a security advisory, CVE or an observed compromise. The offline documentation describes local operation; enabled remote links and integrations require their own data-flow review.

  • No CVE is assigned by this case. Evidence type: documented behaviour.
  • The vendor distinguishes JIT-loaded models from explicitly loaded models. Auto-Evict does not apply indiscriminately to every model in memory.

Primary and supporting records