YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0067

Incident record

LiteLLM AI gateway flaw exploited in the wild for unauthenticated RCE

Severity
Critical
Status
In the wild
Type
Agent Hijack
Target
LiteLLM
Actor
unknown
CVE
CVE-2026-42271

What happened

Horizon3.ai showed that a command-injection flaw in the BerriAI LiteLLM AI gateway, which let any authenticated user run commands on the host through two MCP test endpoints, could be chained with a separate host-header authentication bypass in the Starlette web framework (CVE-2026-48710) to reach unauthenticated remote code execution on servers routing model traffic, rated CVSS 10.0. LiteLLM patched the injection in version 1.83.7 on 19 April 2026, and CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 8 June 2026 with a 22 June remediation deadline.

The injection sits in two MCP preview endpoints, POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list, which accepted a full server configuration including the command to spawn. It was reported to BerriAI by a researcher credited in the project's advisory as jaydns; Horizon3.ai's contribution was chaining it with the Starlette bypass to reach the unauthenticated path. LiteLLM 1.74.2 through 1.83.6 are affected, and Starlette was fixed in 1.0.1. The fix therefore shipped roughly six weeks before the chained research was published and seven weeks before the catalogue listing.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026