CVE-2026-42771 (LiteLLM) exploited in the wild

, ,

Last Updated: 2026-06-10T05:32:42Z

What’s Happening

An April CVE for command execution in LiteLLM 1.83.6 and earlier versions is being exploited by attackers.

The vulnerability has been added to CISA KEVs.

Horizon3 reports the issue is chained with another vulnerability for unauthenticated RCE.

Actions

With three High severity CVEs, IFIN recommends curtailing external access to endpoints using the LiteLLM library.

Notes

The vulnerable endpoints include

  • /mcp-rest/test/connection
  • /mcp-rest/test/tools/list