Skip to content
LiteLLM Flaw Chains to CVSS 10 Unauthenticated RCE

LiteLLM Flaw Chains to CVSS 10 Unauthenticated RCE

Aiweekly.Co June 9, 2026

First-party attack research validating the chain mechanics; confirms Starlette versions up to 1.0.0 strip authentication entirely from LiteLLM's command injection endpoint.

Vulnerability database entry with May 8 discovery timestamp, full affected version range (1.74.2 to 1.83.6), MCP endpoint detection strategies, and containerization workarounds.

Broadest ecosystem framing: maps Starlette's 400,000+ dependents to LiteLLM, vLLM, MCP servers, and agent frameworks as a shared AI infrastructure attack surface.

Adds deployment architecture risk profile: reverse-proxy-fronted instances carry lower exposure; direct network-exposed AI tools are the priority remediation targets.

Defender-focused: lists concrete IoCs including unexpected subprocess execution and malformed Host headers, alongside the exact affected version range 1.74.2 to 1.83.6.

Originally reported by thehackernews.com

Original headline: LiteLLM CVE-2026-42271 Added to CISA KEV — Command Injection Exploited in Wild, CVSS 10.0 Chain Achieves Unauthenticated RCE

Extracted Entities

Attack Types (1)

Platforms (3)

Tools (1)