CVE-2026-42271
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a subprocess on the proxy host with the privileges of the proxy process. The endpoints were gated only by a valid proxy API key, with no role check. Any authenticated user — including holders of low-privilege internal-user keys — could therefore run arbitrary commands on the host. This issue has been patched in version 1.83.7.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Jun 8, 2026
- US federal agencies must remediate it by Jun 22, 2026 (BOD 22-01)
- First attack observed 31 days after disclosure
- Confirmed by sensors, not only by reports
- Used in ransomware campaigns
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Source: CISA KEV · Sep 11, 2026 Sep 10, 2026 Sep 9, 2026 Sep 8, 2026 Sep 7, 2026 Sep 6, 2026
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAffected products
| Vendors | Product | Versions |
|---|---|---|
| litellm | litellm | < 1.83.7 |
| redhat | openshift ai | < 2.25.8 |
Related articles
APTSPECTRE, the backdoor that disables EDRs: inside UAT-10147's arsenal
Recently, Cisco Talos published a two-part analysis of the Chinese-speaking group UAT-10147 , which is active against Windows and Linux web servers on a
VulnerabilitiesSangoma Switchvox Under Attack: Critical SQL Injection Enables Remote Code Execution
CVE-2026-9586 in Sangoma Switchvox exploited via unauthenticated SQL injection at /pa enabling RCE. Update to 8.4.0.2 and hunt for compromise.
VulnerabilitiesPostgreSQL Logical Decoding Flaw Allows Code Execution as the `postgres` User
PostgreSQL CVE-2026-6471 lets REPLICATION users load arbitrary libraries via logical decoding to execute code as postgres. See affected versions and fix.
VulnerabilitiesActively Exploited N-able N-central Flaw Enables Pre-Authentication Remote Code Execution
CISA warns CVE-2026-86218 in N-able N-central is actively exploited, enabling pre-auth RCE. Update to 2026.3 Hotfix 4 immediately.
This product uses the NVD API but is not endorsed or certified by the NVD.