Back

HIGH KEV

LiteLLM: Authenticated command execution via MCP stdio test endpoints

Published May 8, 2026 ·Due Jun 22, 2026

Description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a subprocess on the proxy host with the privileges of the proxy process. The endpoints were gated only by a valid proxy API key, with no role check. Any authenticated user — including holders of low-privilege internal-user keys — could therefore run arbitrary commands on the host. This issue has been patched in version 1.83.7.

Affected products

Remediation

Red Hat statement

This is an Important flaw affecting LiteLLM, as deployed in Red Hat products like Ansible Automation Platform and OpenShift AI. Authenticated users, even with low-privilege API keys, can execute arbitrary commands on the proxy host. This is due to insufficient role checks on specific endpoints that accept server configurations with command execution parameters.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 8, 2026
Updated Jul 15, 2026
Reserved Apr 26, 2026
CISA Vulnrichment
Updated Jun 8, 2026
NVD
Status Analyzed
Modified Jul 15, 2026
Red Hat
Severity Important
Public date May 8, 2026
GHSA-V4P8-MG3P-G94G