CVE-2026-42271Active Exploitation(litellm / litellm)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 47 mentions and remains active

Immediate actions

  • Patch litellm litellm systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a subprocess on the proxy host with the privileges of the proxy process. The endpoints were gated only by a valid proxy API key, with no role check. Any authenticated user — including holders of low-privilege internal-user keys — could therefore run arbitrary commands on the host. This issue has been patched in version 1.83.7.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-06-22. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-77CWE-78

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • litellm
  • openshift_ai

Threat summary

  • Active exploitation appears in 89 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 117 mentions across 43 observed days

What's happening

  • Active exploitation reported across 89 signals
  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 13 signals
  • Patch or workaround mentioned in 41 signals
  • Technical details provided in 90 signals
  • General: 9 classified signals
  • Disclosure: 8 classified signals
  • Peaked 38d ago at 47 mentions (2026-06-09); latest day: 1
  • 117 total mentions across 43 days

Affected systems

Products
litellmopenshift_ai

1 version affected across 2 products

Deep dive

Activity timeline117 mentions / 43d
012243547Mentions · 2026-05-09: 2Mentions · 2026-06-01: 1Mentions · 2026-06-02: 1Mentions · 2026-06-08: 3Mentions · 2026-06-09: 47Mentions · 2026-06-10: 11Mentions · 2026-06-11: 3Mentions · 2026-06-12: 1Mentions · 2026-06-15: 1Mentions · 2026-06-16: 4Mentions · 2026-06-18: 3Mentions · 2026-06-23: 2Mentions · 2026-06-24: 1Mentions · 2026-06-25: 1Mentions · 2026-06-27: 1Mentions · 2026-06-28: 1Mentions · 2026-06-30: 1Mentions · 2026-07-02: 2Mentions · 2026-07-03: 1Mentions · 2026-07-05: 3Mentions · 2026-07-06: 1Mentions · 2026-07-08: 1Mentions · 2026-07-10: 1Mentions · 2026-07-15: 1Mentions · 2026-07-20: 1Mentions · 2026-07-31: 2Mentions · 2026-08-18: 1Mentions · 2026-08-22: 1Mentions · 2026-08-26: 1Mentions · 2026-08-27: 1Mentions · 2026-08-28: 1Mentions · 2026-08-31: 1Mentions · 2026-09-01: 1Mentions · 2026-09-04: 1Mentions · 2026-09-06: 1Mentions · 2026-09-07: 1Mentions · 2026-09-08: 1Mentions · 2026-09-09: 1Mentions · 2026-09-12: 1Mentions · 2026-10-01: 3Mentions · 2026-10-02: 1Mentions · 2026-10-07: 2Mentions · 2026-10-08: 1PoC Mentioned / Linked · 2026-06-09: 7PoC Mentioned / Linked · 2026-06-16: 1PoC Mentioned / Linked · 2026-06-18: 1PoC Mentioned / Linked · 2026-07-05: 1PoC Mentioned / Linked · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-31: 1PoC Mentioned / Linked · 2026-09-04: 1Exploit Tool / Code · 2026-06-09: 1Exploit Tool / Code · 2026-06-16: 1Exploit Tool / Code · 2026-07-06: 1Exploit Tool / Code · 2026-07-31: 1Exploit Tool / Code · 2026-09-04: 1Active Exploitation · 2026-06-08: 2Active Exploitation · 2026-06-09: 42Active Exploitation · 2026-06-10: 10Active Exploitation · 2026-06-11: 3Active Exploitation · 2026-06-12: 1Active Exploitation · 2026-06-15: 1Active Exploitation · 2026-06-16: 3Active Exploitation · 2026-06-18: 3Active Exploitation · 2026-06-23: 2Active Exploitation · 2026-06-24: 1Active Exploitation · 2026-06-27: 1Active Exploitation · 2026-06-28: 1Active Exploitation · 2026-07-02: 2Active Exploitation · 2026-07-03: 1Active Exploitation · 2026-07-05: 1Active Exploitation · 2026-07-06: 1Active Exploitation · 2026-07-10: 1Active Exploitation · 2026-07-15: 1Active Exploitation · 2026-07-20: 1Active Exploitation · 2026-07-31: 2Active Exploitation · 2026-08-18: 1Active Exploitation · 2026-08-26: 1Active Exploitation · 2026-08-27: 1Active Exploitation · 2026-08-28: 1Active Exploitation · 2026-09-01: 1Active Exploitation · 2026-09-06: 1Active Exploitation · 2026-09-07: 1Active Exploitation · 2026-09-09: 1Active Exploitation · 2026-09-12: 1Patch / Workaround · 2026-06-08: 1Patch / Workaround · 2026-06-09: 13Patch / Workaround · 2026-06-10: 4Patch / Workaround · 2026-06-11: 1Patch / Workaround · 2026-06-12: 1Patch / Workaround · 2026-06-16: 3Patch / Workaround · 2026-06-18: 2Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-27: 1Patch / Workaround · 2026-06-28: 1Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-03: 1Patch / Workaround · 2026-07-05: 1Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-08: 1Patch / Workaround · 2026-07-15: 1Patch / Workaround · 2026-07-20: 1Patch / Workaround · 2026-07-31: 2Patch / Workaround · 2026-09-07: 1Patch / Workaround · 2026-09-08: 1Patch / Workaround · 2026-09-09: 1Patch / Workaround · 2026-09-12: 1Technical Details · 2026-05-09: 1Technical Details · 2026-06-08: 2Technical Details · 2026-06-09: 41Technical Details · 2026-06-10: 8Technical Details · 2026-06-11: 2Technical Details · 2026-06-12: 1Technical Details · 2026-06-15: 1Technical Details · 2026-06-16: 4Technical Details · 2026-06-18: 2Technical Details · 2026-06-23: 2Technical Details · 2026-06-25: 1Technical Details · 2026-06-27: 1Technical Details · 2026-06-28: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-02: 2Technical Details · 2026-07-03: 1Technical Details · 2026-07-05: 2Technical Details · 2026-07-06: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-15: 1Technical Details · 2026-07-20: 1Technical Details · 2026-07-31: 2Technical Details · 2026-08-18: 1Technical Details · 2026-08-22: 1Technical Details · 2026-08-26: 1Technical Details · 2026-08-27: 1Technical Details · 2026-08-28: 1Technical Details · 2026-08-31: 1Technical Details · 2026-09-01: 1Technical Details · 2026-09-07: 1Technical Details · 2026-09-08: 1Technical Details · 2026-09-09: 1Technical Details · 2026-09-12: 105-0906-0906-1506-2406-3007-0607-2008-2609-0109-0810-0210-08
Signal classification5 categories
Active Exploitation
8173.6%
General
98.2%
Disclosure
87.3%
Patch
87.3%
Exploit
43.6%
Referenced assets70 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-092
Disclosure1General1
2026-06-011
General1
2026-06-021
General1
2026-06-083
Active Exploitation2Disclosure1
2026-06-0947
Active Exploitation39Disclosure2Exploit1General3Patch2
2026-06-1011
Active Exploitation9General1Patch1
2026-06-113
Active Exploitation3
2026-06-121
Active Exploitation1
2026-06-151
Active Exploitation1
2026-06-164
Active Exploitation3Disclosure1
2026-06-183
Active Exploitation3
2026-06-232
Active Exploitation2
2026-06-241
Active Exploitation1
2026-06-251
Disclosure1
2026-06-271
Active Exploitation1
2026-06-281
Active Exploitation1
2026-06-301
General1
2026-07-022
Active Exploitation2
2026-07-031
Active Exploitation1
2026-07-053
Active Exploitation1Disclosure1Patch1
2026-07-061
Exploit1
2026-07-081
Patch1
2026-07-101
Active Exploitation1
2026-07-151
Active Exploitation1
2026-07-201
Patch1
2026-07-312
Exploit1Patch1
2026-08-181
Active Exploitation1
2026-08-221
General1
2026-08-261
Active Exploitation1
2026-08-271
Active Exploitation1
2026-08-281
Active Exploitation1
2026-08-311
Disclosure1
2026-09-011
Active Exploitation1
2026-09-041
Exploit1
2026-09-061
Active Exploitation1
2026-09-071
Active Exploitation1
2026-09-081
Patch1
2026-09-091
Active Exploitation1
2026-09-121
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Hackers are already exploiting a flaw in LiteLLM, a widely used open-source AI gateway. One bug (CVE-2026-42271) lets any logged-in user run commands on the server. Chain it with a second bug, and attackers get in with no login at all. 🔗 Details: https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html

    Post summary

    Hackers are actively exploiting CVE-2026-42271 in LiteLLM, enabling remote command execution for logged‑in users and facilitating login bypass when chained with another flaw.

    86051565219.5K
    2.0M followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added BerriAI LiteLLM vulnerability CVE-2026-42271 & Check Point Security Gateway vulnerability CVE-2026-50751 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. https://t.co/B3eSaFU0rU

    Post summary

    The tweet announces that CVE-2026-42271 and CVE-2026-50751 have been added to the DHS KEV catalog, indicating they are currently being exploited in the wild, and urges organizations to apply mitigations.

    11712744.9K
    300.6K followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🤖🚨 AI FOUND THE VULNERABILITY. ATTACKERS WEAPONIZED IT FOUR DAYS LATER. Google Threat Intelligence Group has published new data showing how quickly AI-discovered vulnerabilities are crossing into real-world attacks. One case stands out: CVE-2026-1731 The unauthenticated OS command-injection vulnerability affecting BeyondTrust Privileged Remote Access and Remote Support was discovered AUTONOMOUSLY by the Hacktron AI research agent. Then attackers arrived. GTIG observed: * First threat cluster exploiting it within FOUR DAYS of disclosure * Five additional threat clusters within SEVEN DAYS * Privilege escalation * Data exfiltration * SNOWLIGHT deployment * SPARKRAT deployment * Cryptominer deployment But Google's broader dataset may be even more important. Exactly 50% of vulnerabilities identified as AI-discovered resulted in REMOTE CODE EXECUTION. Across the broader vulnerability ecosystem? 26%. AI is also becoming a target itself. GTIG tracked 2,076 AI-related CVEs from January 2025 through August 2026. More than 1,500 appeared in just the first eight months of 2026. The largest attack surface: * 782 vulnerabilities in AI orchestration/agent frameworks * 230 in AI web apps * 212 in inference/serving infrastructure * 106 model-security advisories * 99 affecting ML frameworks/hubs * 97 involving frontier-model tooling Orchestration middleware alone now represents roughly HALF of AI-related vulnerabilities and saw a 347% surge in disclosures during 2026. Attackers are already exploiting AI middleware in the wild. Google highlights: * LiteLLM CVE-2026-42271 — command injection → host takeover/API credential theft * Langflow CVE-2026-5027 — arbitrary file write * Langflow CVE-2025-3248 — unauthenticated Python code injection → RCE ⚠️ Analyst Note: AI is beginning to compress BOTH sides of the vulnerability lifecycle. Defensive agents can autonomously discover difficult, high-impact bugs. Attackers can then weaponize those disclosures almost immediately. Four days from AI discovery disclosure to observed exploitation is a warning about where vulnerability management is heading: PATCH WINDOWS ARE SHRINKING. https://cloud.google.com/blog/topics/threat-intelligence/vulnerability-discovery-and-exploitation-trends-in-the-ai-era #AISecurity #VulnerabilityResearch #RCE #BeyondTrust #LiteLLM #Langflow #ThreatIntel #DDW

    12029106.9K
    206.9K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CISA has added two vulnerabilities to the KEV Catalog https://darkwebinformer.com/cisa-kev-catalog/ CVE-2026-50751: Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. CVE-2026-42271: BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.

    Post summary

    The post announces that CISA has added CVE‑2026‑50751 and CVE‑2026‑42271 to the KEV Catalog, noting their authentication‑bypass and command‑injection weaknesses, but provides no exploit code, patch, or proof‑of‑concept details.

    1201764.6K
    224.2K followersView on X
  • Ritik Chaddha(pwn_box)@RitikChaddha
    General

    We've added Nuclei templates for both CVEs to help quickly validate affected instances. - CVE-2026-42271 (LiteLLM): https://github.com/projectdiscovery/nuclei-templates/pull/16325/changes - CVE-2026-48710 (Starlette BadHost): https://github.com/projectdiscovery/nuclei-templates/pull/16324/changes

    Post summary

    The notification announces the addition of Nuclei detection templates for CVE-2026-42271 and CVE-2026-48710 to help quickly validate affected instances.

    040972.4K
    444 followersView on X
  • Modat@modat_magnify
    Patch

    ⚠️ LiteLLM – Command Injection via MCP Preview Endpoints (CVSS 8.7, CISA KEV)  CISA has added CVE-2026-42271 to its KEV catalogue. The vulnerability affects LiteLLM, a widely deployed AI gateway proxy.  Two preview endpoints could be tricked into running attacker-supplied commands directly on the proxy host. Because they only required a valid API key with no permission check, any authenticated user could execute arbitrary commands on the server.  Affected versions: LiteLLM 1.74.2 up to (not including) 1.83.7  Mitigation: Upgrade to LiteLLM 1.83.7 or later. Federal agencies must remediate by June 22, 2026. Restrict and audit API key issuance, and limit proxy exposure to trusted users only.  Modat Magnify Query: product="LiteLLM API" OR product="LiteLLM"  The platform: https://magnify.modat.io/  #threatintel #vulnerability #CVE202642271 #LiteLLM #CommandInjection #RCE #infosec #KEV #ModatMagnify

    Post summary

    CISA lists CVE-2026-42271 as a command‑injection flaw in LiteLLM with potential active exploitation; users should upgrade to version 1.83.7 or later and enforce strict API key controls.

    140811.3K
    1.7K followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html

    Post summary

    CVE-2026-42271 in LiteLLM is reported to be actively exploited, leading to unauthenticated remote code execution. The text does not mention PoC, exploit code, or patch information.

    020341.7K
    158.9K followersView on X
  • Sara@SMCADMAN

    The bambino is only targeting high-performance backend server infrastructure, he needs the processing power for cryptocurrency mining, great piece of malware 🤷‍♀️🤣 🦀♋️ driver = 92, diode = 119, decryption = 165, string = 74 #PoeLLM CVE-2026-42271 *tickles @grok @XSecurity @DOGE @elonmusk @michaelo @teddemop 😏

    12220164
    6.6K followersView on X
  • piyokango@piyokango
    Exploit

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(6/8追加) 🛡No.1614 CVE-2026-42271 BerriAI LiteLLM Command Injection Vulnerability ==================================== ✅概要 ・深刻度:重要 8.8 (CVSS Base) / NVD ・種別:OSコマンドインジェクション (CWE-78) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H LiteLLM 1.74.2 以上 1.83.7 未満に存在するコマンドインジェクションの脆弱性です。 MCP サーバー保存前プレビュー用の POST /mcp-rest/test/connection および POST /mcp-rest/test/tools/list が、stdio transport の command、args、env を含む構成を受け付け、プロキシプロセス権限で指定コマンドをサブプロセスとして実行する可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・LiteLLM 1.74.2 以上 1.83.7 未満を使用している ・攻撃者が有効な LiteLLM proxy API key を保持している ・対象エンドポイントへネットワーク経由でリクエストを送信できる ・対象エンドポイントが PROXY_ADMIN ロール確認なしで利用可能な状態である ✅悪用時影響 ・LiteLLM プロキシホスト上で任意 OS コマンドを実行される ・プロキシプロセス権限で機密情報を読み取られる ・ホスト上のデータを改ざんされる ・サービス停止や追加侵害につながる可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み ・ITW:未確認 公開 GitHub リポジトリ上で、MCP stdio test endpoint に transport、command、args を含むリクエストを送信し、LiteLLM 1.82.6 の検証環境でコマンド実行を確認する PoC が確認。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-42271 ・https://github.com/BerriAI/litellm/security/advisories/GHSA-v4p8-mg3p-g94g ・https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable 🛡No.1615 CVE-2026-50751 Check Point Security Gateway Improper Authentication Vulnerability ==================================== ✅概要 ・深刻度:緊急 9.3 (CVSS Base) / CISA-ADP ・種別:不適切な認証 (CWE-287) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N Check Point Security Gateway の Remote Access VPN および Mobile Access における認証不備の脆弱性です。 非推奨の IKEv1 key exchange における証明書検証のロジック不備により、事前認証されていない攻撃者がリモートから有効なユーザーパスワードなしで VPN 接続を確立できる恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅攻撃前提条件 ・Check Point Remote Access VPN または Mobile Access を使用している ・非推奨の IKEv1 key exchange が構成されている ・影響を受けるバージョンの Security Gateway または Spark Firewall を使用している ・修正済み hotfix または緩和策が適用されていない ✅悪用時影響 ・ユーザー認証を回避される ・有効なユーザーパスワードなしでリモートアクセス VPN 接続を確立される ・VPN 接続後の追加操作により内部リソースへ到達される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み(Check Point Research) Check Point Research は、CVE-2026-50751 の実環境での悪用を確認し、観測された悪用は世界で数十組織程度に限定され、Qilin ランサムウェア関連の侵害後活動が確認された事例があると公表。攻撃開始時期の調査では、2026年5月7日を最も早い観測日としてログ監査を行うよう推奨。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-50751 ・https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/ ・https://support.checkpoint.com/results/sk/sk185033 https://www.cisa.gov/news-events/alerts/2026/06/08/cisa-adds-two-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The entry lists two CVEs added to CISA’s KEV catalog, details a command‑injection flaw in LiteLLM with a public PoC on GitHub, confirms active exploitation of a Check Point VPN authentication flaw, and includes vendor patches and advisories.

    000425.5K
    44.0K followersView on X
  • Alex Remniov@alexremn
    Active Exploitation

    Your AI gateway might be the biggest hole in your infra. CVE-2026-42271: unauth RCE in LiteLLM — one request, attacker gets every model API key configured. On CISA KEV since Jun 27. One proxy for all LLM traffic = perfect target. Running LiteLLM in prod — patched yet?

    Post summary

    CVE‑2026‑42271 is a known unauthenticated remote code execution flaw in LiteLLM, flagged by CISA as actively exploited; the post suggests it remains unpatched.

    0014016.5K
    36 followersView on X
  • The Agentic Daily@theagenticdaily
    Active Exploitation

    A critical bug in LiteLLM lets attackers skip authentication and call MCP tools directly - CVE-2026-59822, CVSS 8.8, now on CISA's Known Exploited Vulnerabilities list. Anyone routing AI agents through LiteLLM should upgrade to v1.84.0 or later immediately; it can also be chained with a separate command-injection bug (CVE-2026-42271).

    Post summary

    LiteLLM's CVE-2026-59822 allows authentication bypass and direct MCP tool calls, is actively exploited per CISA, and requires an immediate upgrade to version 1.84.0 or newer.

    10020148
    94 followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Active Exploitation

    LiteLLM vulnerability under active attack, CISA warns (CVE-2026-42271) https://www.helpnetsecurity.com/2026/06/09/litellm-vulnerability-under-active-attack-cisa-warns-cve-2026-42271/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    CISA warns that CVE‑2026‑42271 in LiteLLM is currently being exploited; no PoC, patch, or technical details are disclosed.

    01011392
    194.6K followersView on X
  • Horizon3.ai@Horizon3ai
    General

    The chain combines: • CVE-2026-42271 (LiteLLM) • CVE-2026-48710 (Starlette BadHost)

    Post summary

    The text merely lists two CVE identifiers without providing any additional details or context.

    10020187
    2.8K followersView on X
  • CloudSecurityAlliance@cloudsa
    Active Exploitation

    CISO Daily Briefing: Aurora ransomware ran Cursor's coding agent for AD enumeration & NTLM relay on 10+ victims. Wiz: CVE-2026-59822+CVE-2026-42271 give unauth RCE on LiteLLM/MCP, harvesting API keys; 90% orgs hit. 700 OpenAI agents self-coordinated to breach Hugging Face via reward hacking. Gov: NIST SP 1353 pushes AI for compliance work, leaves data-handling undefined (comments to Oct 15). TeamPCP arrests close Shai-Hulud; 500K+ creds exposed, copycats emerging. https://labs.cloudsecurityalliance.org/research/ciso-daily-briefing-20260901/

    Post summary

    The briefing reports that CVE-2026-59822 and CVE-2026-42271 provide unauthenticated remote code execution against LiteLLM/MCP, with widespread exploitation affecting 90% of organizations, complemented by AI‑driven attacks on other platforms.

    01010539
    18.9K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Microsoft observed active exploitation of AI infrastructure: LiteLLM, RAGFlow, and Kestra deployments compromised for credential theft, persistence, and cryptomining across three distinct intrusion chains. Key findings: - LiteLLM gateway compromise chained CVE-2026-42271 (authenticated command execution via MCP stdio) with CVE-2026-48710 (Starlette host-header bypass) for unauthenticated RCE. Attackers read /proc/1/environ for provider API keys and DATABASE_URL, then dumped LiteLLM_ProxyModelTable and LiteLLM_VerificationToken from Azure PostgreSQL via a Python one-liner. Persistence via SSH authorized_keys write, cron, and chattr +i on payload dirs. MITRE: T1190, T1552.001, T1098.004, T1053.003. - RAGFlow intrusion began with SSRF probing to oast[.]me infrastructure, followed days later by code execution inside the Flask runtime. A Python hook injected into api/__init__.py intercepted provider credentials (OpenAI, Azure, Anthropic, Gemini) on every TenantLLM.insert() call and exfiltrated them to 135.125.10[.]56:19888. - Kestra exploitation used CVE-2026-49869 (critical auth bypass) to submit a malicious workflow, spawning bash from the Java worker. Attackers accessed the mounted Docker socket to enumerate container Config.Env arrays across all running containers, then deployed XMRig v6.26.0 toward auto.c3pool[.]org. Output stored via Kestra's own KV API. - C2 and exfil domains: yosemite[.]jp, gobygo[.]net, oast[.]pro/fun/me. #DFIR_Radar

    Post summary

    Microsoft reported real‑world exploitation of three AI platforms using CVEs for credential theft and cryptomining, detailing the attack chains and technical methods.

    20000198
    1.9K followersView on X
  • Neerav Ahuja@Neerav_Ahuja18
    General

    AI Gateways (like LiteLLM) store real provider keys (sk-...) so developers only handle virtual keys. If a proxy master key leaks or an instance is unpatched (CVE-2026-42271): 1.) Reroute Traffic: Calling /model/update sets api_base to a rogue proxy and use_litellm_proxy: true. 2.) Steal Provider Keys: When the gateway resolves the real Authorization: Bearer <sk-...> header, it sends it straight to the attacker. 3.) Forge Tool Calls: Attacker hooks (async_post_call_success_hook) inject malicious tool calls (e.g., Bash execution) into AI agent clients. Because the tool call is injected downstream of the model, prompt-level guardrails NEVER see it. Day 28 Days of AI Security Until I Hack ChatGPT #AISecurity #RedTeaming #BugBounty #LLMSecurity

    Post summary

    The post discloses CVE-2026-42271 in AI gateways like LiteLLM, detailing exploitation vectors to steal provider keys and inject malicious tool calls, but no PoC, patch, or active attack reports are presented.

    00020160
    13 followersView on X
  • Creators' AI@crtrsai
    Patch

    CISA flagged a LiteLLM flaw (CVE-2026-42271): an unauthenticated RCE that leaks every OpenAI/Anthropic API key configured in the gateway. Patch NOW. https://t.co/xDdBSam6GO

    Post summary

    The tweet announces a CVE (CVE-2026-42271) involving an unauthenticated RCE that exposes all OpenAI/Anthropic API keys in a LiteLLM gateway, highlights that CISA has flagged the issue, and urges immediate patching.

    20000109
    733 followersView on X
  • Cybersecurity News Alerts@secureblognews
    Active Exploitation

    🚨 CISA adds the #LiteLLM AI Gateway RCE flaw (CVE-2026-42271) to KEV. This exploit grants a zero-click root shell, exposing master API keys &amp; all internal AI prompts. Full technical breakdown &amp; mitigation guide here: 👉 https://cyberupdates365.com/litellm-critical-rce-vulnerability-cve-2026-42271/ #CyberSecurity #InfoSec #ai

    Post summary

    The tweet announces that CVE-2026-42271 has been added to the CISA KEV list, indicating it is being actively exploited with a zero‑click root shell, and cites a technical breakdown and mitigation guide.

    01010184
    25 followersView on X
  • elorri_79@456c6f727269
    Active Exploitation

    🚨 New critical LiteLLM flaw is being exploited in the wild. CVE-2026-42271 (CVSS 8.7) — command injection via two MCP preview endpoints. Chained with CVE-2026-48710 (Starlette host header bypass) → unauthenticated RCE (CVSS 10.0). If you run litellm-proxy: read this thread. 🧵👇

    Post summary

    LiteLLM CVE-2026-42271 (command injection, CVSS 8.7) is reported to be actively exploited in the wild, with chaining to CVE-2026-48710 for RCE. No patch, PoC, or exploit tool is detailed in the post.

    1000184
    99 followersView on X
  • Help Net Security@helpnetsecurity
    Active Exploitation

    LiteLLM vulnerability under active attack, CISA warns (CVE-2026-42271) - https://www.helpnetsecurity.com/2026/06/09/litellm-vulnerability-under-active-attack-cisa-warns-cve-2026-42271/ - @CISACyber @CISAgov @Horizon3ai #AI #LLMs #OpenSource #Proxy #Vulnerability #Cybersecurity #CybersecurityNews

    Post summary

    The post confirms that CVE-2026-42271 is being actively exploited in the wild, as warned by CISA, but offers no further technical or patch details.

    00011283
    60.1K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Applitellmlitellm---
Appredhatopenshift_ai---
Appredhatopenshift_ai3.4--

Explore more