CVE-2026-30623Patch

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration specifying arbitrary command and args values. LiteLLM executes these values on the host without validation, enabling attackers to run arbitrary operating system commands. Successful exploitation may result in remote code execution with the privileges of the LiteLLM process.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 14 mentions across 11 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 12 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 7d ago at 2 mentions (2026-06-05); latest day: 1
  • 14 total mentions across 11 days

Deep dive

Activity timeline14 mentions / 11d
01122Mentions · 2026-04-22: 1Mentions · 2026-05-03: 1Mentions · 2026-05-10: 1Mentions · 2026-06-05: 2Mentions · 2026-06-19: 2Mentions · 2026-06-21: 1Mentions · 2026-07-17: 2Mentions · 2026-07-20: 1Mentions · 2026-07-22: 1Mentions · 2026-07-25: 1Mentions · 2026-08-03: 1PoC Mentioned / Linked · 2026-07-22: 1Exploit Tool / Code · 2026-07-22: 1Active Exploitation · 2026-05-10: 1Active Exploitation · 2026-07-20: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-05-03: 1Patch / Workaround · 2026-06-05: 2Patch / Workaround · 2026-07-17: 2Patch / Workaround · 2026-07-20: 1Patch / Workaround · 2026-07-22: 1Patch / Workaround · 2026-07-25: 1Technical Details · 2026-05-03: 1Technical Details · 2026-05-10: 1Technical Details · 2026-06-05: 2Technical Details · 2026-06-19: 1Technical Details · 2026-06-21: 1Technical Details · 2026-07-17: 2Technical Details · 2026-07-20: 1Technical Details · 2026-07-22: 1Technical Details · 2026-07-25: 1Technical Details · 2026-08-03: 104-2205-0305-1006-0506-1906-2107-1707-2007-2207-2508-03
Signal classification5 categories
Patch
535.7%
Disclosure
535.7%
General
214.3%
Active Exploitation
17.1%
PoC
17.1%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-221
Patch1
2026-05-031
General1
2026-05-101
Active Exploitation1
2026-06-052
Disclosure1Patch1
2026-06-192
Disclosure1General1
2026-06-211
Disclosure1
2026-07-172
Patch2
2026-07-201
Patch1
2026-07-221
PoC1
2026-07-251
Disclosure1
2026-08-031
Disclosure1
Full discourse14 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-30623 - high 🚨 LiteLLM 1.18.10 - Command Injection > LiteLLM 1.18.10 contains a remote code execution caused by lack of validation of arbi... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-30623 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces a high‑severity command injection flaw in LiteLLM 1.18.10, describes the vulnerability’s nature, but provides no exploit code, patch information, or evidence of active exploitation.

    19028132.3K
    1.3K followersView on X
  • LiteLLM (YC W23)@LiteLLM
    Patch

    CVE-2026-30623 (vulnerability via Anthropic's MCP SDK) has been fixed since v1.83.6-nightly. Please refer to our blog post for more details. https://docs.litellm.ai/blog/mcp-stdio-command-injection-april-2026

    Post summary

    CVE-2026-30623 was fixed in version v1.83.6‑nightly of Litellm, with additional details available in the linked blog post.

    11021791
    5.1K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - LiteLLM MCP stdio Command Injection (CVE-2026-30623) LiteLLM versions prior to 1.83.7 allow authenticated users to create or update MCP servers using the stdio transport. By supplying arbitrary command and args in the JSON config, the server passes them directly to Anthropic’s MCP SDK StdioServerParameters, which spawns the command as a subprocess on the proxy host. This enables authenticated remote code execution as the LiteLLM process. Affected: >=1.74.2 and <v1.83.7-stable Fixed in: v1.83.7-stable (first stable release) 👉 Upgrade to LiteLLM v1.83.7-stable or later.

    Post summary

    The notice discloses a remote code execution vulnerability in LiteLLM versions <1.83.7 and recommends upgrading to v1.83.7-stable or later to remediate the issue.

    00010114
    254 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Severity vs Product vs Vector: CVE-2026-30615: Critical (vs Product Windsurf IDE | Vector Zero-click prompt injection → local RCE) CVE-2026-30623: Critical (vs Product LiteLLM | Vector Authenticated RCE via JSON config) CVE-2026-26030: Critical (vs Product Semantic Kernel…

    Post summary

    The text lists three newly disclosed critical CVEs, detailing their affected products, severity, and exploitation vectors such as zero‑click prompt injection and authenticated RCE via JSON configuration.

    1000057
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    @AutoGPT @crewai CVE-2026-30623 just hit. You're running agents blind. We're not.

    Post summary

    The tweet merely announces that CVE‑2026‑30623 has been disclosed, with no further details, links, or evidence of exploitation.

    1000047
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    15:54 UTC: CVE-2026-30623 disclosed. The Foundation Is the Vulnerability: How MCP's Architectural RCE Flaw Put 200,000 AI Servers at Risk Ox Security published research on April 15, 2026 revealing an architectural RCE vulnerability baked directly into Anthropic's Model…

    Post summary

    CVE-2026-30623, an architectural RCE flaw in Anthropic's model, has been publicly disclosed on April 15, 2026; no PoC, exploit code, patch, or active exploitation details are provided.

    1000047
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Six live production platforms were compromised during responsible disclosure testing. LiteLLM (CVE-2026-30623, Critical, patched), Windsurf (CVE-2026-30615, Critical, reported), Bisheng (CVE-2026-33224, Critical, patched), and DocsGPT (CVE-2026-26015, Critical, patched)…

    Post summary

    Six production platforms were compromised during responsible disclosure testing, with several CVEs identified as critical and patched, while one remains reported.

    1000046
    246 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Immediate (0-48h): Patch all MCP-connected platforms against the OX Security CVE list: priority CVE-2026-30615 (zero-click Windsurf), CVE-2026-30623 (LiteLLM authenticated RCE), CVE-2026-26015 (DocsGPT MITM) Block public IP access to all LLM/AI enabler services; restrict…

    Post summary

    An advisory urging immediate patching of multiple newly identified CVEs in AI platforms, providing vulnerability types but no PoC or exploitation evidence.

    1000063
    246 followersView on X
  • Sattyam Jain@Sattyamjjain
    General

    CVE-2026-30623 (LiteLLM), CVE-2026-30615 (Windsurf), CVE-2026-30617 (Langchain-Chatchat) all hit the same shape: a tool call resolves to shell. The MCP-STDIO transport doesn't bound it. You bound it, or you get bounded.

    Post summary

    The post highlights that CVE‑2026‑30623, CVE‑2026‑30615, and CVE‑2026‑30617 allow unbounded tool calls to spawn shell, presenting a remote code execution risk that can be mitigated by bounding the MCP‑STDIO transport.

    1000047
    67 followersView on X
  • foursignals@foursignalsdev
    Disclosure

    MCP's STDIO transport: a single mcp.json can execute shell commands (CVE-2026-30623). 200,000+ instances at risk. Switch to remote transports with auth. https://www.foursignals.dev/wire/2026-07-25/model-context-protocol-through-the-agent-stack-lens-what-5575e7

    Post summary

    The text announces the discovery of CVE-2026-30623, highlights its impact, recommends switching to authenticated remote transports, and outlines a practical workaround.

    0000035
    31 followersView on X
  • Rapid Risk Radar@rapidriskradar
    PoC

    LiteLLM MCP RCE (CVE-2026-30623) — crafted JSON for MCP servers can execute arbitrary OS commands. CVSS 9.8, PoC available. Mitigate: block MCP network access, run under least privilege, isolate containers, and patch ASAP. Details → https://app.rapidriskradar.com/cve/CVE-2026-30623 https://t.co/pTybEfDHHB

    Post summary

    CVE‐2026‐30623 is a high‑severity RCE in LiteLLM MCP, with a PoC available that demonstrates arbitrary OS command execution; mitigation involves network isolation and prompt patching.

    0000048
    15 followersView on X
  • Emphere@empherehq
    Patch

    Two LiteLLM MCP stdio command-injection CVEs had the same root cause and the same April fix. CVE-2026-42271 made KEV in June because its reachability was different: any valid API key versus CVE-2026-30623's narrow config path. CVE feeds flatten that. Attackers do not. #CVE-2026-30623 #CVE-2026-42271

    Post summary

    Two related LiteLLM command‑injection CVEs share the same root cause and were fixed in April; CVE‑2026‑42271’s inclusion in KEV in June signals its higher exploitation risk.

    0000035
    7 followersView on X
  • Moez Sr.@moezshabbir
    Patch

    Security note for AI infra folks: CVE-2026-30623 just landed -- a critical RCE in LiteLLM (1.74.2 to before 1.83.7) via stdio transport in MCP configs. Patched in 1.83.7-stable. If you route model calls through it, update today. #AIsecurity #LLM #DevOps

    Post summary

    CVE-2026-30623 is a critical remote code execution flaw in LiteLLM, fixed in version 1.83.7‑stable; users should update immediately.

    0000051
    356 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    🔴 #4 — MCP Protocol Architectural RCE 150M+ downloads. ~200K production AI servers exposed. CVE-2026-30623 (LiteLLM), CVE-2026-30615 (Windsurf) + 10 more. Anthropic's response: "expected behavior." LangChain, Cursor, VS Code, Gemini-CLI — all affected.

    Post summary

    A large‑scale MCP Protocol architectural RCE (CVE-2026-30623/30615) has exposed around 200K production AI servers, with no immediate patch or PoC offered and vendor noting "expected behavior."

    00000100
    197 followersView on X

Explore more