CVE-2026-42271: CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') in BerriAI litellm
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a subprocess on the proxy host with the privileges of the proxy process. The endpoints were gated only by a valid proxy API key, with no role check. Any authenticated user — including holders of low-privilege internal-user keys — could therefore run arbitrary commands on the host. This issue has been patched in version 1.83.7.
AI Analysis
Technical Summary
LiteLLM is a proxy server for calling LLM APIs. Versions from 1.74.2 to before 1.83.7 contain a command injection vulnerability in the POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list endpoints. These endpoints accept a full server configuration including command, args, and env fields used by the stdio transport. When a stdio configuration is provided, the server spawns the supplied command as a subprocess with the proxy process privileges. The endpoints require only a valid proxy API key without role checks, allowing any authenticated user, including those with low-privilege internal-user keys, to execute arbitrary commands on the host. The vulnerability is fixed in version 1.83.7.
Potential Impact
An attacker with any valid proxy API key, including low-privilege keys, can execute arbitrary commands on the proxy host with the privileges of the proxy process. This can lead to full system compromise, data theft, or disruption of service. The CVSS 4.0 score is 8.7 (high severity), reflecting network attack vector, low attack complexity, partial privileges required, no user interaction, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A fix is available in LiteLLM version 1.83.7. Users should upgrade to version 1.83.7 or later to remediate this vulnerability. There is no indication that temporary mitigations or workarounds are provided by the vendor. Review and restrict API key usage to minimize exposure until patching is complete.
CVE-2026-42271: CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') in BerriAI litellm
Description
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a subprocess on the proxy host with the privileges of the proxy process. The endpoints were gated only by a valid proxy API key, with no role check. Any authenticated user — including holders of low-privilege internal-user keys — could therefore run arbitrary commands on the host. This issue has been patched in version 1.83.7.
CVSS v4.0
Score 8.7high
Affected software
pkg:github/berriai/litellmRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
LiteLLM is a proxy server for calling LLM APIs. Versions from 1.74.2 to before 1.83.7 contain a command injection vulnerability in the POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list endpoints. These endpoints accept a full server configuration including command, args, and env fields used by the stdio transport. When a stdio configuration is provided, the server spawns the supplied command as a subprocess with the proxy process privileges. The endpoints require only a valid proxy API key without role checks, allowing any authenticated user, including those with low-privilege internal-user keys, to execute arbitrary commands on the host. The vulnerability is fixed in version 1.83.7.
Potential Impact
An attacker with any valid proxy API key, including low-privilege keys, can execute arbitrary commands on the proxy host with the privileges of the proxy process. This can lead to full system compromise, data theft, or disruption of service. The CVSS 4.0 score is 8.7 (high severity), reflecting network attack vector, low attack complexity, partial privileges required, no user interaction, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A fix is available in LiteLLM version 1.83.7. Users should upgrade to version 1.83.7 or later to remediate this vulnerability. There is no indication that temporary mitigations or workarounds are provided by the vendor. Review and restrict API key usage to minimize exposure until patching is complete.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-04-26T11:53:27.707Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-42271","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:28960","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:30056","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27784","vendor":"Red Hat"}]
Threat ID: 69fd5dbdcbff5d86108b6463
Added to database: 05/08/2026, 03:51:25 UTC
Last enriched: 07/15/2026, 09:15:52 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 128
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.