Tools AI Risk Radar ai-incident-0067
Incident record
LiteLLM AI gateway flaw exploited in the wild for unauthenticated RCE
- Severity
- Critical
- Status
- In the wild
- Type
- Agent Hijack
- Target
- LiteLLM
- Actor
- unknown
- CVE
- CVE-2026-42271
What happened
Horizon3.ai showed that a command-injection flaw in the BerriAI LiteLLM AI gateway, which let any authenticated user run commands on the host through two MCP test endpoints, could be chained with a separate host-header authentication bypass in the Starlette web framework (CVE-2026-48710) to reach unauthenticated remote code execution on servers routing model traffic, rated CVSS 10.0. LiteLLM patched the injection in version 1.83.7 on 19 April 2026, and CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 8 June 2026 with a 22 June remediation deadline.
The injection sits in two MCP preview endpoints, POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list, which accepted a full server configuration including the command to spawn. It was reported to BerriAI by a researcher credited in the project's advisory as jaydns; Horizon3.ai's contribution was chaining it with the Starlette bypass to reach the unauthenticated path. LiteLLM 1.74.2 through 1.83.6 are affected, and Starlette was fixed in 1.0.1. The fix therefore shipped roughly six weeks before the chained research was published and seven weeks before the catalogue listing.
Sources
- Horizon3.ai: CVE-2026-42271 chained with CVE-2026-48710, LiteLLM unauthenticated remote code execution (1 June 2026)horizon3.ai/attack-research/vulnerabilities/cve-2026-42271-c…
- GitHub security advisory GHSA-v4p8-mg3p-g94g: command execution via LiteLLM MCP stdio test endpointsgithub.com/BerriAI/litellm/security/advisories/GHSA-v4p8-mg3…
- GitHub security advisory GHSA-86qp-5c8j-p5mr: Starlette missing Host header validation (CVE-2026-48710)github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c…
- LiteLLM release v1.83.7-stablegithub.com/BerriAI/litellm/releases/tag/v1.83.7-stable
- CISA Known Exploited Vulnerabilities catalogue (JSON feed)www.cisa.gov/sites/default/files/feeds/known_exploited_vulne…
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026