LiteLLM MCP preview endpoints allow authenticated users to run commands on proxy host
CVE-2026-42271: LiteLLM versions 1.74.2 through 1.83.6 exposed two MCP server preview endpoints that accepted a full stdio server configuration and spawned the supplied command as a subprocess on the proxy host. The endpoints required only a valid proxy API key with no role check, so any authenticated user, including low-privilege internal users, could achieve arbitrary command execution; fixed in 1.83.7.
Disclosed 8 May 2026 · Record updated 13 September 2026
Impact
Any holder of a valid proxy API key, including low-privilege internal-user keys, could execute arbitrary commands on the LiteLLM proxy host with the privileges of the proxy process.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42271
