LiteLLM CVE-2026-42271 被列入 CISA KEV:MCP 测试端点命令注入可链式触发未授权 RCE
Original title: CISA KEV: CVE-2026-42271 in LiteLLM, authenticated command injection via MCP test endpoints, chains to unauthenticated RCE (CVSS 10.0)
The title and summary in the selected language are awaiting translation.
CISA 于 2026 年 6 月 8 日将 BerriAI LiteLLM 的 CVE-2026-42271 列入 KEV 目录,要求 6 月 22 日前修复。
材料完整还原了 LiteLLM 从 MCP 测试端点命令注入到未授权 RCE 的利用链与补丁版本,可据此排查自身网关部署。
2026-06-08
CriticalMedia report
CISA KEV: CVE-2026-42271 in LiteLLM, authenticated command injection via MCP test endpoints, chains to unauthenticated RCE (CVSS 10.0)
CISA added CVE-2026-42271 in BerriAI LiteLLM to its KEV catalog June 8, 2026. MCP test endpoints allow authenticated command injection, chains to unauthenticated RCE via Starlette BadHost bypass.
BerriAI LiteLLMTool execution / MCPCommand injection / Remote code execution via AI gatewayLiteLLM proxy host, model provider credentials (OpenAI/Anthropic/etc. API keys), connected AI infrastructure
What happened
Attacker POSTs a crafted server config (command: reverse-shell, args, env) to /mcp-rest/test/connection; LiteLLM spawns the command as a subprocess with proxy-process privileges. When chained with Starlette Host header bypass, no credentials required.
Why it matters
Full host shell access; exfiltration of all model provider API keys stored in the proxy; lateral movement into every AI system behind the LiteLLM gateway; downstream credential compromise of connected OpenAI, Anthropic, and other LLM provider accounts.
Missing authorization check
Not applicable: no agent authorization boundary was crossed in this incident.
Would PP block it?
The compromise ran through package, credential, or vendor infrastructure rather than through an agent tool call, so there is no agent action for an authorization gate to hold.
Incident analysis
Timeline and technical read
Timeline
2026-05-26
CVE-2026-48710 (Starlette BadHost) disclosed — the authentication bypass component
2026-06-08
CISA adds CVE-2026-42271 to KEV catalog; due date June 22, 2026
2026-06-08
Horizon3.ai publishes exploit chain — CVE-2026-42271 + CVE-2026-48710 yields unauthenticated RCE, combined CVSS 10.0
2026-06-09
The Hacker News reports active exploitation; LiteLLM 1.83.7 patch (PROXY_ADMIN role required) already available
2026-06-10
Widespread media coverage; automated scanning tools targeting exposed LiteLLM deployments confirmed
Technical breakdown
- Affected endpoints: POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list accepted a full MCP server config including command, args, and env fields for stdio transport — effectively an arbitrary subprocess launcher
- Authentication bypass: CVE-2026-48710 (Starlette ≤1.0.0 BadHost header bypass) strips authentication entirely, transforming an authenticated-user exploit into zero-credential RCE
- Privilege inheritance: spawned subprocess runs with full privileges of the LiteLLM proxy process — in containerized deployments often running as root or with broad IAM permissions
- Credential exposure: LiteLLM stores model provider API keys in memory/config; shell access on the proxy host yields all keys for OpenAI, Anthropic, Azure, etc. gated behind the proxy
- Patch: LiteLLM 1.83.7 now requires PROXY_ADMIN role for the test endpoints; Starlette 1.0.1 patches the host header bypass
Authorization boundary
Where the authorization boundary should have been
This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
- If enforced at
- PP enforcement sits above the LiteLLM proxy — agent actions are gate-checked before being routed to the gateway. The vulnerable endpoints are below this boundary.
- Still needs
- Infrastructure-layer hardening of the AI gateway itself. PP does not govern LiteLLM deployment configuration, authentication posture, or patch cadence. Deployment hygiene is out of scope.
- Receipt required for
- Any agent action that spawns OS-level subprocesses, configures MCP server transports, or reads/writes LiteLLM proxy credentials must carry a receipt naming the specific operation and target host.
No agent took an action in this incident. Permission Protocol gates what an agent does, so it does not apply where the harm required no agent action.
Start small
Put the relevant gate at this action boundary.
This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.
Source: Permission Protocol · AI Agent Incident Tracker · permissionprotocol.com