CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2026-42271Public Exploit

LiteLLM - RCE (CVE-2026-42271)

PublishedMay 8, 2026
First SeenJul 2, 2026
Last Seen
Reported
CVSS8.7
ai_mcpweb_application

Description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a subprocess on the proxy host with the privileges of the proxy process. The endpoints were gated only by a valid proxy API key, with no role check. Any authenticated user — including holders of low-privilege internal-user keys — could therefore run arbitrary commands on the host. This issue has been patched in version 1.83.7.

psychologyCrowdSec Analysis

CVE-2026-42271 is a remote code execution vulnerability in BerriAI's LiteLLM proxy server, affecting versions 1.74.2 through 1.83.6. The flaw allows any authenticated user, even those with low-privilege internal-user keys, to execute arbitrary commands on the proxy host by abusing the POST /mcp-rest/test/connection and /mcp-rest/test/tools/list endpoints. Attackers could exploit this to gain unauthorized control over the server, potentially leading to data breaches or further compromise of the environment. This critical issue has been addressed in version 1.83.7.

CrowdSec has been tracking this vulnerability and its exploits since 1st of July 2026.

According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2026-42271 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting. Data from the CrowdSec community also indicates a gradual decrease in attacks targeting CVE-2026-42271. While still present in the wild, exploitation levels have dropped noticeably week-over-week. This may signal that the vulnerability is becoming less relevant or that defenses are improving fast enough for attackers to lose interest.

Attackers exploit the /mcp-rest/test/connection endpoint by sending crafted JSON payloads to trigger command injection, enabling remote code execution on vulnerable LiteLLM servers. This endpoint is targeted directly, often in combination with authentication bypass techniques, to gain unauthenticated access and execute arbitrary commands.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-05-08
CISA KEV2026-06-08
CISA Remediation Deadline2026-06-22
Rule Released2026-07-01
CrowdSec First Seen2026-07-02

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.