LiteLLM: Authenticated command execution via MCP stdio test endpoints
Published May 8, 2026 ·Due Jun 22, 2026
8.7
HIGHCVSS 4.0
EPSS 92.57%
Description
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a subprocess on the proxy host with the privileges of the proxy process. The endpoints were gated only by a valid proxy API key, with no role check. Any authenticated user — including holders of low-privilege internal-user keys — could therefore run arbitrary commands on the host. This issue has been patched in version 1.83.7.
Affected products
-
- Version >= 1.74.2, < 1.83.7StatusaffectedConstraints-
- Version
Configuration 2
- ≥ 2.25 · < 2.25.8
- ≥ 3.3 · < 3.3.4
- 3.4
No data.
Red Hat OpenShift AI 2.25
rhoai/odh-llama-stack-core-rhel9:1781826406
Fixed · RHSA-2026:28960
Red Hat OpenShift AI 3.3
rhoai/odh-llama-stack-core-rhel9:1782310008
Fixed · RHSA-2026:30056
Red Hat OpenShift AI 3.4
rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9:1781622627
Fixed · RHSA-2026:27784
Exploit Intelligence
exploit-intelligence-tech-preview/vulnerability-analysis-rhel9
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-26/lightspeed-chatbot-rhel9
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-27/lightspeed-chatbot-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mlflow-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift AI 2.25 | rhoai/odh-llama-stack-core-rhel9:1781826406 | Fixed | RHSA-2026:28960 |
| Red Hat OpenShift AI 3.3 | rhoai/odh-llama-stack-core-rhel9:1782310008 | Fixed | RHSA-2026:30056 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9:1781622627 | Fixed | RHSA-2026:27784 |
| Exploit Intelligence | exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/lightspeed-chatbot-rhel9 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-27/lightspeed-chatbot-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mlflow-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This is an Important flaw affecting LiteLLM, as deployed in Red Hat products like Ansible Automation Platform and OpenShift AI. Authenticated users, even with low-privilege API keys, can execute arbitrary commands on the proxy host. This is due to insufficient role checks on specific endpoints that accept server configurations with command execution parameters.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
Date Added
Jun 8, 2026
Patch Due
Jun 22, 2026
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jun 8, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
May–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 92.57% (0.92570) | 99.83th | v5 (v2026.06.15) |
| Sep 20, 2026 | 83.59% (0.83594) | 99.67th | v5 (v2026.06.15) |
| Jul 24, 2026 | 83.01% (0.83013) | 99.64th | v5 (v2026.06.15) |
| Jul 1, 2026 | 80.19% (0.80188) | 99.57th | v5 (v2026.06.15) |
| Jun 23, 2026 | 74.99% (0.74993) | 99.44th | v5 (v2026.06.15) |
| Jun 15, 2026 | 53.70% (0.53701) | 98.86th | v5 (v2026.06.15) |
| Jun 9, 2026 | 60.78% (0.60784) | 98.32th | v4 (v2025.03.14) |
| Jun 3, 2026 | 4.12% (0.04116) | 88.81th | v4 (v2025.03.14) |
| May 8, 2026 | 0.05% (0.00047) | 14.31th | v4 (v2025.03.14) |
References (13)
- https://access.redhat.com/errata/RHSA-2026:27784 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:28960 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:30056 Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-42271 Third Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2467924 Third Party AdvisoryIssue Tracking
- https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable x_refsource_MISCProductRelease Notes
- https://github.com/BerriAI/litellm/security/advisories/GHSA-v4p8-mg3p-g94g x_refsource_CONFIRMMitigationPatchVendor Advisory
- https://github.com/advisories/GHSA-v4p8-mg3p-g94g Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-42271
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42271.json Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42271 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2026-42271
Change history (0)
No recorded changes yet.