REDHAT-BUG-2467924: High severity LiteLLM vulnerability

Published May 8, 2026
·
Updated

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a subprocess on the proxy host with the privileges of the proxy process. The endpoints were gated only by a valid proxy API key, with no role check. Any authenticated user — including holders of low-privilege internal-user keys — could therefore run arbitrary commands on the host. This issue has been patched in version 1.83.7.

Affected Software

1 affected component
LiteLLM>=1.74.2<1.83.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade LiteLLM to a version that resolves this vulnerability.

    Fixed in 1.83.7
  2. Compensating control

    Ensure proxy API keys are not accessible to low-privilege users; apply authorization so only trusted roles can invoke the /mcp-rest/test/connection and /mcp-rest/test/tools/list endpoints (these endpoints were gated only by a valid proxy API key with no role check).

Event History

May 8, 2026
Data Sourced
via Red Hat·04:02 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Who can exploit this issue?

Any user with a valid LiteLLM proxy API key can exploit it, including users holding low-privilege internal-user keys. The affected endpoints did not enforce a role check.

2

What does an attacker need to do to achieve code execution?

The attacker must send a request to either affected MCP preview endpoint with a stdio server configuration containing a chosen command, arguments, and environment values. LiteLLM then spawns the supplied command on the proxy host using the proxy process's privileges.

3

Are systems running the patched release affected?

No. The issue is patched in LiteLLM version 1.83.7; the affected range is version 1.74.2 through versions before 1.83.7.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203