LiteLLM - RCE (CVE-2026-42271)
Description
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a subprocess on the proxy host with the privileges of the proxy process. The endpoints were gated only by a valid proxy API key, with no role check. Any authenticated user — including holders of low-privilege internal-user keys — could therefore run arbitrary commands on the host. This issue has been patched in version 1.83.7.
psychologyCrowdSec Analysis
CVE-2026-42271 is a remote code execution vulnerability in BerriAI's LiteLLM proxy server, affecting versions 1.74.2 through 1.83.6. The flaw allows any authenticated user, even those with low-privilege internal-user keys, to execute arbitrary commands on the proxy host by abusing the POST /mcp-rest/test/connection and /mcp-rest/test/tools/list endpoints. Attackers could exploit this to gain unauthorized control over the server, potentially leading to data breaches or further compromise of the environment. This critical issue has been addressed in version 1.83.7.
CrowdSec has been tracking this vulnerability and its exploits since 1st of July 2026.
According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2026-42271 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting. Data from the CrowdSec community also indicates a gradual decrease in attacks targeting CVE-2026-42271. While still present in the wild, exploitation levels have dropped noticeably week-over-week. This may signal that the vulnerability is becoming less relevant or that defenses are improving fast enough for attackers to lose interest.
Attackers exploit the /mcp-rest/test/connection endpoint by sending crafted JSON payloads to trigger command injection, enabling remote code execution on vulnerable LiteLLM servers. This endpoint is targeted directly, often in combination with authentication bypass techniques, to gain unauthenticated access and execute arbitrary commands.
Full Intelligence Available
Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.
| Event | Date |
|---|---|
| CVE Published | 2026-05-08 |
| CISA KEV | 2026-06-08 |
| CISA Remediation Deadline | 2026-06-22 |
| Rule Released | 2026-07-01 |
| CrowdSec First Seen | 2026-07-02 |
Remediation & Protection
External References
- https://access.redhat.com/errata/RHSA-2026:28960
- https://bugzilla.redhat.com/show_bug.cgi?id=2467924
- https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable
- https://access.redhat.com/errata/RHSA-2026:30056
- https://access.redhat.com/errata/RHSA-2026:27784
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42271.json
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42271
- https://github.com/BerriAI/litellm/security/advisories/GHSA-v4p8-mg3p-g94g
- https://access.redhat.com/security/cve/CVE-2026-42271
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-42271.yaml