CVE-2026-42271High· 8.8▾ Abyssal⚠ Exploited in the wildPoC availableLiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /m…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 48.4 · likelihood 16.7 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Jun 22, 2026
Last analysed / modified upstream
80%
80% → 84%
2 GitHub repos · Nuclei ×1
Added to the CISA catalog on Jun 8, 2026. Federal remediation due Jun 22, 2026. View catalog ↗
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a subprocess on the proxy host with the privileges of the proxy process. The endpoints were gated only by a valid proxy API key, with no role check. Any authenticated user — including holders of low-privilege internal-user keys — could therefore run arbitrary commands on the host. This issue has been patched in version 1.83.7.
litellm >= 1.74.2, < 1.83.7openshift_ai >= 2.25, < 2.25.8openshift_ai >= 3.3, < 3.3.4openshift_ai = 3.4Upgrade past the affected range:
litellm 1.83.7openshift_ai 3.3.4Affected packages:
litellm >= 1.74.2, < 1.83.7Patched in:
litellm 1.83.7Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-42208Critical· 9.8LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format
CVE-2026-42203HighLiteLLM: Server-Side Template Injection in /prompts/test endpoint
CVE-2026-59822High· 8.2LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format
CVE-2026-37004Critical· 9.8LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
CVE-2026-59820Medium· 6.5LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format
CVE-2026-35030Critical· 9.1LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format