CVE-2026-42271
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a subprocess on the proxy host with the privileges of the proxy process. The endpoints were gated only by a valid proxy API key, with no role check. Any authenticated user — including holders of low-privilege internal-user keys — could therefore run arbitrary commands on the host. This issue has been patched in version 1.83.7.
22 articles across 6 outlets · first covered Jun 8, 2026 · latest Jun 15, 2026
Coverage timeline
-
CISA warns of exploits in LiteLLM and Check Point VPN flawssocradar.io · Jun 9, 2026
-
LiteLLM, Check Point Flaws Hit as MagicAd Trojan Surgessecurityonline.info · Jun 9, 2026
-
Check Point VPN flaw under attack as Google slashes AI Plus pricesecurityonline.info · Jun 9, 2026
-
CISA Flags Critical Flaws in LiteLLM and Check Point VPN Gatewayssecurityaffairs.com · Jun 9, 2026
-
Check Point VPN bug lets attackers hijack open source downloadssecurityonline.info · Jun 9, 2026
-
Critical flaws CVE-2026-42271/50751 exploited in Zlibrary mirrorssecurityonline.info · Jun 9, 2026
-
Microsoft updates OneDrive policy amid LiteLLM, Check Point flawssecurityonline.info · Jun 9, 2026
-
LiteLLM flaw CVE-2026-42271 lets hackers execute code remotelythehackernews.com · Jun 9, 2026
-
Apple iOS 27 Adds AI Password Reset Amid Two Critical CVEssecurityonline.info · Jun 9, 2026
-
Check Point VPN flaw hits as OpenAI files for $1 trillion IPOsecurityonline.info · Jun 9, 2026
-
Apache MINA Patches Critical Framework Vulnerabilitiessecurityonline.info · Jun 9, 2026
-
Pragmatic Refinement: Apple Rebalances Aesthetics and Performance at WWDC 2026securityonline.info · Jun 9, 2026
-
Sovereign Synthesis: Apple Unveils Gemini-Powered Siri AI and macOS Golden Gatesecurityonline.info · Jun 9, 2026
-
Apache HTTP Server 2.4.68 fixes critical bugs to protect systemssecurityonline.info · Jun 9, 2026
-
Critical Flaws Hit LiteLLM Check Point and TP Link Devicessecurityonline.info · Jun 9, 2026
-
CISA warns of LiteLLM command injection flaw CVE-2026-42271www.cisa.gov · Jun 9, 2026
-
CISA Active Exploit Catalog Expands with Critical Gateway Flawssecurityonline.info · Jun 9, 2026
-
New Chrome Security Update Addresses Critical V8 Exploit in the Wildsecurityonline.info · Jun 9, 2026
-
Malicious PyPI Package Wave Spreads Evolving Supply Chain Attackssecurityonline.info · Jun 9, 2026
-
Sovereign Intelligence: Apple Reimagines Siri with Gemini Core Integration at WWDC 2026securityonline.info · Jun 9, 2026
-
Unveils AI Powered iOS 27 and macOS 27 Amid Critical CVE Alertssecurityonline.info · Jun 9, 2026
-
CISA warns of LiteLLM command injection flaw CVE-2026-42271cisa.gov · Jun 8, 2026