Last Updated: 2026-06-10T05:32:42Z
What’s Happening
An April CVE for command execution in LiteLLM 1.83.6 and earlier versions is being exploited by attackers.
The vulnerability has been added to CISA KEVs.
Horizon3 reports the issue is chained with another vulnerability for unauthenticated RCE.
Actions
With three High severity CVEs, IFIN recommends curtailing external access to endpoints using the LiteLLM library.
Notes
The vulnerable endpoints include
/mcp-rest/test/connection/mcp-rest/test/tools/list