# CVE-2026-42271: LiteLLM - RCE

> Live exploitation tracking for CVE-2026-42271 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-42271

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 8.7
- **Public exploit available:** Yes
- **Affected products:** BerriAI LiteLLM
- **Weaknesses:** CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))
- **Tags:** ai_mcp, web_application

## Description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a subprocess on the proxy host with the privileges of the proxy process. The endpoints were gated only by a valid proxy API key, with no role check. Any authenticated user — including holders of low-privilege internal-user keys — could therefore run arbitrary commands on the host. This issue has been patched in version 1.83.7.

## CrowdSec analysis

[CVE-2026-42271](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-42271) is a remote code execution vulnerability in BerriAI's LiteLLM proxy server, affecting versions 1.74.2 through 1.83.6. The flaw allows any authenticated user, even those with low-privilege internal-user keys, to execute arbitrary commands on the proxy host by abusing the POST /mcp-rest/test/connection and /mcp-rest/test/tools/list endpoints. Attackers could exploit this to gain unauthorized control over the server, potentially leading to data breaches or further compromise of the environment. This critical issue has been addressed in version 1.83.7.

CrowdSec has been tracking this vulnerability and its exploits since 1st of July 2026.

According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2026-42271 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting.
Data from the CrowdSec community also indicates a gradual decrease in attacks targeting CVE-2026-42271. While still present in the wild, exploitation levels have dropped noticeably week-over-week. This may signal that the vulnerability is becoming less relevant or that defenses are improving fast enough for attackers to lose interest.

Attackers exploit the `/mcp-rest/test/connection` endpoint by sending crafted JSON payloads to trigger command injection, enabling remote code execution on vulnerable LiteLLM servers. This endpoint is targeted directly, often in combination with authentication bypass techniques, to gain unauthenticated access and execute arbitrary commands.

## Timeline

- 2026-05-08: CVE Published. CVE-2026-42271 is published to NVD.
- 2026-06-08: CISA KEV. CVE-2026-42271 is added to the Known Exploited Vulnerabilities catalog by CISA.
- 2026-06-22: CISA Remediation Deadline. Expiration of the CISA remediation deadline as described in [BOD 22-01](https://www.cisa.gov/news-events/directives/bod-22-01-reducing-significant-risk-known-exploited-vulnerabilities).
- 2026-07-01: Rule Released. CrowdSec releases a rule to detect CVE-2026-42271 exploitation attempts against the CrowdSec Network.
- 2026-07-02: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-42271 for the first time.

## References

- https://access.redhat.com/errata/RHSA-2026:28960
- https://bugzilla.redhat.com/show_bug.cgi?id=2467924
- https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable
- https://access.redhat.com/errata/RHSA-2026:30056
- https://access.redhat.com/errata/RHSA-2026:27784
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42271.json
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42271
- https://github.com/BerriAI/litellm/security/advisories/GHSA-v4p8-mg3p-g94g
- https://access.redhat.com/security/cve/CVE-2026-42271
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-42271.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-42271) follows observed exploitation activity for CVE-2026-42271. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
