PT-2026-37185 · Litellm · Litellm

·

CVE-2026-42271

·

Published

2026-04-25

·

Updated

2026-07-20

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LiteLLM versions 1.74.2 through 1.83.6
Description LiteLLM is a proxy server (AI Gateway) used to call LLM APIs in OpenAI or native format. The endpoints 'POST /mcp-rest/test/connection' and 'POST /mcp-rest/test/tools/list', used to preview an MCP server, accept a full server configuration in the request body. This includes the command, args, and env variables used by the stdio transport. When a stdio configuration is provided, the endpoints spawn the supplied command as a subprocess on the proxy host with the privileges of the proxy process. Because these endpoints only require a valid proxy API key and lack role checks, any authenticated user, including those with low-privilege internal-user keys, can execute arbitrary commands on the host. This issue has been actively exploited in the wild.
Recommendations Update to version 1.83.7. As a temporary workaround, block the 'POST /mcp-rest/test/connection' and 'POST /mcp-rest/test/tools/list' endpoints at the reverse proxy or API gateway.

Exploit

Fix

RCE

LPE

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42271
ECHO-C4C7-AED2-2231
GHSA-V4P8-MG3P-G94G
PYSEC-2026-2599

Affected Products

Litellm