chiprook
← Security
SecuritySeptember 25, 2026, 08:20

LiteLLM auth bypass: a one-character token unlocked MCP tools

LiteLLM carried CVE-2026-59822, an improper authentication flaw where a failed token check returned an empty auth object, so any bearer token — even a single character — passed. Chained with CVE-2026-42271 and CVE-2026-48710 it yields unauthenticated remote code execution; the fix ships in version 1.84.0.

LiteLLM auth bypass: a one-character token unlocked MCP tools
#LiteLLM#Starlette#Wiz#CISA
Read next
Security

ZoomEye finds 2.7 million Home Assistant installs exposed online

Security

Codex Desktop flaw let untrusted code read auth tokens from shared memory

Security

ZoomEye: 9,112 Indexed Kafka Endpoints vs 1,377,501 Services on Port 9092

Security

Hackers Claim Theft of FBI Data With Employee Home Addresses