CVE-2026-42271
Last modified
CVE-2026-42271 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. CISA has confirmed active exploitation in the wild. EPSS estimates a 80.19% chance of exploitation in the next 30 days.
Description
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a subprocess on the proxy host with the privileges of the proxy process. The endpoints were gated only by a valid proxy API key, with no role check. Any authenticated user — including holders of low-privilege internal-user keys — could therefore run arbitrary commands on the host. This issue has been patched in version 1.83.7.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Litellm | Litellm | >= 1.74.2, < 1.83.7 |
| Redhat | Openshift Ai | >= 2.25, < 2.25.8 |
| Redhat | Openshift Ai | >= 3.3, < 3.3.4 |
| Redhat | Openshift Ai | 3.4 |
References
- https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stableProduct, Release Notes
- https://github.com/BerriAI/litellm/security/advisories/GHSA-v4p8-mg3p-g94gMitigation, Patch, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:27784Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:28960Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:30056Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-42271Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2467924Third Party Advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42271.jsonThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42271US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-42271?
How severe is CVE-2026-42271?
How do I fix CVE-2026-42271?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-42261PromptHub is an all-in-one AI toolbox for prompt, skill, and…7.1
- CVE-2026-42264Axios is a promise based HTTP client for the browser and Nod…9.1
- CVE-2026-42266JupyterLab is an extensible environment for interactive and …8.8
- CVE-2026-42267Kimai is an open-source time tracking application. From vers…5.7
- CVE-2026-42268ModSecurity is an open source, cross platform web applicatio…7.5
- CVE-2026-4227A security vulnerability has been detected in LB-LINK BL-WR9…7.5
- CVE-2026-42272Heimdall is a cloud native Identity Aware Proxy and Access C…7.8
- CVE-2026-42273Heimdall is a cloud native Identity Aware Proxy and Access C…7.8
- CVE-2026-42274Heimdall is a cloud native Identity Aware Proxy and Access C…7.8
- CVE-2026-42275zrok is software for sharing web services, files, and networ…8.7
- CVE-2026-42276Onyx is an open-source AI platform. Prior to versions 3.0.9,…4.3
- CVE-2026-42277Onyx is an open-source AI platform. Prior to versions 3.0.9,…6.5
Are you affected by CVE-2026-42271?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
