Threat · curated 1 Oct 2026

When the AI Gateway Becomes the Weakest Link: Command Execution in LiteLLM's MCP Test Endpoints

Dossier

Coverage timeline

1 Oct 2026dev.to

Single-source incident — first reported, latest, and curated coincide.

Why it matters

LiteLLM is a widely deployed AI gateway that concentrates model credentials and routing, so arbitrary command execution as root via a low-privilege key hands attackers full control of production AI infrastructure.

CVE-2026-42271 is an authorization and command-execution flaw in LiteLLM's MCP test endpoints (/mcp-rest/test/connection and /mcp-rest/test/tools/list), present from version 1.74.2 and fixed in 1.83.7. The endpoints only checked for a valid proxy API key with no role check, and the stdio transport launched caller-supplied commands via subprocess with no allowlist, letting a low-privilege virtual key run arbitrary commands as the proxy process (root in official Docker images). CISA added it to the Known Exploited Vulnerabilities catalog, confirming exploitation in the wild.

exploited-vuln

Summary

CVE-2026-42271 is a command-execution vulnerability in LiteLLM's MCP (Model Context Protocol) management/test endpoints that was confirmed exploited in the wild and added to CISA's Known Exploited Vulnerabilities catalog on June 8, 2026. The flaw stems from two compounding design mistakes: an authorization gap in which the endpoints verified only that a caller presented a valid proxy API key without any role check, and a wholly open execution surface in which the stdio transport launched a subprocess from caller-supplied command, args, and env values with no allowlist.[0]

Because any valid virtual key — even one scoped to a single model with a small budget — could reach these endpoints, a low-privilege caller could execute arbitrary commands with the privileges of the LiteLLM proxy process. Since the official Docker images run the proxy as root, this amounts to remote code execution as root on the gateway host, which concentrates every model credential in the environment.[0]

The vulnerability was not exploited in isolation. Researchers documented a chain combining an authentication bypass (CVE-2026-59822) and a Starlette request-smuggling host-header bypass (CVE-2026-48710) with CVE-2026-42271 as the execution primitive, yielding unauthenticated RCE against internet-reachable AI gateways, with observed post-exploitation deploying a Python downloader and a miner.[0]

Attack chain

  1. Initial access / authentication bypass: In the documented chain, a single-character Bearer token bypasses MCP gateway authentication via CVE-2026-59822, and a Starlette request-smuggling issue (CVE-2026-48710) provides a host header bypass, enabling unauthenticated reach to the management interface.[0]
  2. Privilege/authorization gap: The MCP test endpoints checked only for a valid proxy API key and performed no role check, so a low-privilege virtual key had the same access as an administrator key.[0]
  3. Code execution: For the stdio transport the gateway used subprocess to launch a child process from caller-supplied command, args, and env with no allowlist, giving arbitrary command execution as the proxy process (root in the official Docker images).[0]
  4. Post-exploitation: Attackers submitted forged MCP server configurations whose command field launched a Python downloader and a miner while the test endpoint returned a normal-looking handshake to mask the abuse, and read the memory of running Python processes to recover the LiteLLM master key.[0]
  5. Persistence: Related intrusions reportedly included modifying SSH keys, tampering with cron, disguising processes under normal service names, setting immutable file attributes, and installing startup hooks that survive reboots.[0]

Disclosure timeline

DateEvent
Version 1.74.2LiteLLM introduced the MCP management endpoints, marking the start of the affected version range.[0]
Version 1.83.7Fix released, requiring the PROXY_ADMIN role for both endpoints and adding a validate_transport_fields() allowlist on the stdio command field.[0]
June 8, 2026CISA added CVE-2026-42271 to the Known Exploited Vulnerabilities catalog, confirming exploitation in the wild.[0]

How it works

For the stdio MCP transport, an MCP server configuration contains the executable, arguments, and environment variables needed to launch the server — effectively an exec(command, args, env) call. The protocol does not specify who may supply that command, leaving the decision to the gateway implementation.[0]

The affected implementation made two sequential mistakes. First, the /mcp-rest/test/connection and /mcp-rest/test/tools/list endpoints checked only whether the caller presented a valid proxy API key and performed no role check, so a virtual key from /key/generate had the same access as an admin key. Second, when the transport was stdio, the gateway used subprocess to spawn a child process from the caller-supplied command, args, and env with no allowlist, allowing arbitrary command execution.[0]

Process spawning and command execution occur before the MCP JSON-RPC handshake completes, so the endpoint can return HTTP 200 with a body reporting that the connection failed even though the injected command already ran. Execution should be judged by side effects — a written file, outbound connection, or callback — rather than by the response body.[0]

The 1.83.7 patch required the PROXY_ADMIN role for both endpoints and added a validate_transport_fields() check that allowlists the stdio command field to only npx, uvx, python, python3, node, docker, and deno.[0]

Affected versions and patch status

ProductAffectedPatch status
LiteLLM (MCP test endpoints)Versions from 1.74.2 up to, but not including, 1.83.7Fixed in 1.83.7 (GHSA-v4p8-mg3p-g94g). Independent testing noted the published version range may not perfectly match observed behavior across every patch release, so verify the actual deployed version.[0]

Indicators of Compromise

TypeIndicatorContext
cveCVE-2026-42271LiteLLM MCP test-endpoint command execution primitive, added to CISA KEV on June 8, 2026.[0]
cveCVE-2026-59822Single-character Bearer token MCP gateway authentication bypass used in the exploitation chain.[0]
cveCVE-2026-48710Starlette request smuggling / host header bypass used in the exploitation chain.[0]
otherTest endpoint returns a connection error while a child process has already runBehavioral signature worth alerting on; correlate gateway logs with process creation events and outbound network activity.[0]

Key takeaways

  • Management and preview features deserve the same threat modeling as the data path; a convenience endpoint that validates a configuration can hand an attacker a host-level command-execution primitive.[0]
  • AI gateways concentrate credentials, routing, and administrative reach, so a single authorization gap on them carries outsized impact — here, RCE as root on the host holding every model credential.[0]
  • A valid API key is not the same as administrative authority; authentication without role-based authorization enabled low-privilege callers to invoke privileged execution endpoints.[0]

Defensive actions

  • Upgrade to a fixed LiteLLM release (at least 1.83.7), preferring a version that covers the broader chain rather than the minimum patch for this single CVE, and verify the actual deployed version.: The fix adds the PROXY_ADMIN role check and the stdio command allowlist; the CVE was chained with CVE-2026-59822 and CVE-2026-48710 for unauthenticated RCE.[0]
  • Enforce explicit role checks after authentication on any endpoint that starts processes, touches credentials, changes configuration, or reaches external services.: The root cause was that a valid key was treated as administrative authority; a low-privilege virtual key had the same access as an admin key.[0]
  • Apply an allowlist on executable names for any feature that spawns subprocesses from user-supplied configuration.: An allowlist meaningfully reduces blast radius even for legitimate administrators, as adopted in the 1.83.7 validate_transport_fields() check.[0]
  • Do not expose the AI gateway to the internet; place it behind authentication and network controls and restrict access to management and test interfaces.: An internet-reachable AI gateway is an execution surface, and the proxy runs as root in official Docker images.[0]
  • Alert on the behavioral tell — a test endpoint returning a connection error while a child process has already run — and correlate gateway logs with process creation and outbound network activity.: Command execution happens before the MCP handshake completes, so the misleading response body can mask abuse.[0]