CVE-2026-42271 in LiteLLM: RCE via MCP test endpoints
In LiteLLM 1.74.2–1.83.6, MCP test endpoints checked only for a valid API key, with no role check, and launched arbitrary commands via the stdio transport. CISA added CVE-2026-42271 to its Known Exploited Vulnerabilities catalog on June 8, 2026; patch 1.83.7 requires the PROXY_ADMIN role and adds a command allowlist.
- Affected range: LiteLLM 1.74.2 up to 1.83.7, fix in 1.83.7
- CVSS 8.8 (v3.1) and 8.7 (v4.0), exploited in the wild
- Official Docker images run the proxy as root
- Attack chain also uses CVE-2026-59822 and CVE-2026-48710
Read next
Security