## Overview
LiteLLM, a proxy server for LLM APIs, is vulnerable to a critical exploit identified as CVE-2026-42271. This vulnerability allows authenticated users to execute arbitrary commands on the host system. The affected versions range from 1.74.2 to just before 1.83.7. The exploit has been weaponized, making immediate action necessary.
## Technical Details
The vulnerability resides in two endpoints: POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list. These endpoints accept a full server configuration in the request body, including command, args, and env fields. When invoked with a stdio configuration, they attempt to connect, which results in the execution of the supplied command as a subprocess. This occurs with the privileges of the proxy process. The only requirement for exploitation is a valid proxy API key. There is no role check, allowing even low-privilege users to exploit this vulnerability.
## Impact
The CVSS score for this vulnerability is 8.7, indicating a high severity level. Successful exploitation could lead to complete compromise of the host system, allowing attackers to execute arbitrary commands. This poses a significant risk to organizations using LiteLLM, especially those with low-privilege internal users who may inadvertently trigger the exploit.
## Mitigation
Defenders should upgrade to LiteLLM version 1.83.7, where the vulnerability has been patched. Additionally, review API key management practices to limit access to trusted users only. Implement network segmentation and monitoring to detect unusual activity related to the proxy server.
CSURFACE Threat Sensor