Critical Alert 2 Active Exploits Detected Today

CVE-2026-42271 BerriAI LiteLLM Command Injection Vulnerability →
CVE-2026-50751 Check Point Security Gateway Improper Authentication Vulnerability →
Powered by CVE Watchtower
×

Critical Alert

CVE-2026-50751 - Critical Check Point VPN Exploit Discovered Active in the Wild. View Threat Details →
Powered by CVE WATCHTOWER
×

CVE Watchtower


← Back to CVE List

CVE-2026-42271NVD

Vulnerability Summary

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it β€” POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list β€” accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a subprocess on the proxy host with the privileges of the proxy process. The endpoints were gated only by a valid proxy API key, with no role check. Any authenticated user β€” including holders of low-privilege internal-user keys β€” could therefore run arbitrary commands on the host. This issue has been patched in version 1.83.7.
Severity Level
UNKNOWN
Published Date
Apr 25, 2026
Last Modified
Jun 8, 2026
Exploitation Status
????
EPSS Score (30-Day)
4.12%Probability
Root Weakness (CWE)
N/A