First-party attack research validating the chain mechanics; confirms Starlette versions up to 1.0.0 strip authentication entirely from LiteLLM's command injection endpoint.
Vulnerability database entry with May 8 discovery timestamp, full affected version range (1.74.2 to 1.83.6), MCP endpoint detection strategies, and containerization workarounds.
Broadest ecosystem framing: maps Starlette's 400,000+ dependents to LiteLLM, vLLM, MCP servers, and agent frameworks as a shared AI infrastructure attack surface.
Adds deployment architecture risk profile: reverse-proxy-fronted instances carry lower exposure; direct network-exposed AI tools are the priority remediation targets.
Defender-focused: lists concrete IoCs including unexpected subprocess execution and malformed Host headers, alongside the exact affected version range 1.74.2 to 1.83.6.
Originally reported by thehackernews.com
Original headline: LiteLLM CVE-2026-42271 Added to CISA KEV — Command Injection Exploited in Wild, CVSS 10.0 Chain Achieves Unauthenticated RCE
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
