logo

LiteLLM Vulnerability Allows Attackers to Execute Arbitrary Commands on Servers

ID: 4f9f578f-90b6-54a8-b1e3-eec1f5248f22

STIX ID: report--4f9f578f-90b6-54a8-b1e3-eec1f5248f22

Feed Name: GBHackers

Threat Score
95/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: Divya

...
...

A critical command-injection vulnerability (CVE-2026-42271) in LiteLLM's MCP test endpoints can be chained with a Starlette Host-header validation bug (CVE-2026-48710, “BadHost”) to achieve unauthenticated remote code execution (CVSS 10.0). Affected LiteLLM releases (1.74.2–1.83.6) should be upgraded to 1.83.7+ and Starlette to 1.0.1+; organizations should also restrict access to MCP test endpoints, rotate credentials, and monitor for suspicious Host headers and subprocess executions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.