---
schema: 1
kind: vulnerability
title: "CVE-2026-42271 — BerriAI LiteLLM: low-privilege command injection to host RCE, added to CISA KEV"
headline: "CVE-2026-42271 — BerriAI LiteLLM: low-privilege command injection to host RCE, added to CISA KEV"
summary: "LiteLLM AI-gateway command injection (CVE-2026-42271) added to CISA KEV — host RCE via the MCP test endpoints, unauthenticated when chained with CVE-2026-48710; fixed in 1.83.7 (GitHub Advisory)."
discovered_at: "2026-06-09T05:00:03Z"
event_date: 2026-06-01
run_id: 2026-06-09-40d562df
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - rce
  - cisa-kev
  - ai-abuse
regions:
  - global
sectors:
  - technology
entities: []
techniques:
  - T1190
  - T1059
cves:
  - id: CVE-2026-42271
    cvss: "8.7"
    epss: null
    type: rce
    vector: zero-click
    auth: post-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
  - id: CVE-2026-48710
    cvss: "6.5"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://github.com/advisories/GHSA-v4p8-mg3p-g94g"
    publisher: GitHub Advisory GHSA-v4p8-mg3p-g94g
    role: primary
  - url: "https://horizon3.ai/attack-research/vulnerabilities/cve-2026-42271-chained-with-cve-2026-48710/"
    publisher: Horizon3.ai analysis
    role: corroborating
  - url: "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"
    publisher: "CISA"
    date: "2026-09-02"
    role: corroborating
closed_sources: []
evidence:
  - quote: "When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a subprocess on the proxy host with the privileges of the proxy process."
    publisher: "GitHub Advisory GHSA-v4p8-mg3p-g94g"
verification: multi-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: B
  credibility: 1
watchlist_hit: false
actions:
  - "**Upgrade LiteLLM to 1.83.7 (CVE-2026-42271)** — KEV-listed, actively exploited; unauthenticated when chained with CVE-2026-48710. Restrict the `/mcp-rest/test/*` endpoints at the network layer and audit API-key scoping in the interim."
migrated_from: briefs/2026-06-09.md
updates:
  - at: "2026-09-01T04:20:00Z"
    run_id: 2026-09-01T0411Z-intel
    type: correction
    summary: >
      The cves[] record for CVE-2026-42271 carried cvss: n/a and vector: user-interaction,
      inconsistent with this entry's own CVE Summary Table (which already showed CVSS 8.7)
      and with GHSA-v4p8-mg3p-g94g, which this entry already cites as primary. Corrected to
      cvss: 8.7, vector: zero-click, matching the source and the entry's own table. This
      pre-v3.18 migrated entry also carried no techniques[] and no classification block;
      added techniques: [T1190, T1059] (the exploited MCP test endpoints and the resulting
      host command execution) and classification {reliability: B, credibility: 1} per the
      entry's own multi-source corroboration, and replaced an evidence[] quote that had been
      mislabeled as a verbatim GHSA excerpt with an actual verbatim excerpt from that source.
    fields: [cves, techniques, classification, evidence]
    internal: true
  - at: "2026-09-06T14:05:00Z"
    run_id: 2026-09-06T1308Z-audit
    type: improvement
    internal: true
    summary: >
      CVE-2026-48710's record disagreed with Starlette's own GitHub Security Advisory and with the
      store's dedicated entry for the same flaw on four fields. The advisory publishes CVSS 6.5
      (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N), whose PR:N and UI:N make it pre-auth and
      zero-click; the score was absent here and the vector and authentication prerequisite were
      recorded as user-interaction and post-auth, and the type as rce rather than an auth bypass.
      All four are aligned to the advisory.
    fields: [cves]
  - at: "2026-09-13T14:45:00Z"
    run_id: 2026-09-13T1307Z-audit
    type: improvement
    internal: true
    summary: >
      CVE-2026-48710's cves[] record carried the exploited and cisa-kev flags with no source that
      states either. Neither cited source supports them: the GitHub Advisory covers CVE-2026-42271,
      and Horizon3.ai's analysis is dated 2026-06-01, three months before the listing. CISA added
      CVE-2026-48710 to the KEV catalog on 2026-09-02, so the flags are correct today; the catalog
      is now cited for them. The flags were carried uncited from this entry's June migration, which
      means they asserted a KEV listing that did not yet exist for three months.
    fields: [sources]
---

CISA added CVE-2026-42271 to its KEV catalog on 8 June 2026, confirming active exploitation of a command-injection flaw in LiteLLM, the open-source AI gateway/proxy widely deployed to multiplex LLM API calls in enterprise AI stacks ([GitHub Advisory GHSA-v4p8-mg3p-g94g](https://github.com/advisories/GHSA-v4p8-mg3p-g94g)). Two preview endpoints — `POST /mcp-rest/test/connection` and `POST /mcp-rest/test/tools/list` — accept a full MCP server configuration (command, args, env) in the request body; with stdio transport, the proxy spawns the supplied command on the host under the proxy's privileges. The endpoints were gated only by a valid API key with no role check, so any authenticated user (including low-privilege internal keys) could execute arbitrary commands. Horizon3.ai documents that chaining with CVE-2026-48710 (a Starlette Host-header validation bypass) makes the path unauthenticated ([Horizon3.ai, 2026-06-01](https://horizon3.ai/attack-research/vulnerabilities/cve-2026-42271-chained-with-cve-2026-48710/)). Affected: LiteLLM 1.74.2 to < 1.83.7; fixed in 1.83.7, which adds role-based authorization on the MCP test endpoints.


#### CVE Summary Table

| CVE | Product | CVSS | EPSS | KEV | Exploited | Patch | Source |
|---|---|---|---|---|---|---|---|
| CVE-2026-50751 | Check Point Security Gateway (IKEv1 Remote Access / Mobile Access VPN) | 9.3 | n/a | Yes (2026-06-08) | Yes (since 2026-05-07, Qilin affiliate) | Hotfix sk185033 | [Check Point](https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/) |
| CVE-2026-42271 | BerriAI LiteLLM proxy (1.74.2 → < 1.83.7) | 8.7 | n/a | Yes (2026-06-08) | Yes (CISA-confirmed) | Upgrade to 1.83.7 | [GitHub Advisory](https://github.com/advisories/GHSA-v4p8-mg3p-g94g) |
