Threat reportVulnerabilityTL-2026-0738

CVE-2026-42271: LiteLLM MCP Server Command Injection Under Active Exploitation, Chained with CVE-2026-48710 (Starlette BadHost) for Unauthenticated RCE

criticalACTIVE

CVE-2026-42271 (TL-2026-0738), also tracked as BadHost, is a critical-severity software vulnerability scored CVSS 8.8, first published 2026-06-09 and last reviewed 2026-08-27. It has no confirmed attribution, affects BerriAI LiteLLM, references 2 CVEs (CVE-2026-42271, CVE-2026-48710), maps to 24 MITRE ATT&CK techniques (T1005, T1036, T1041), and is covered by 9 detection rules and 33 indicators of compromise.

CVSS
8.8/10Critical
CVEs
2Referenced vulnerabilities
Techniques
24MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
33Indicators of compromise

Key facts for TL-2026-0738

Threat ID
TL-2026-0738
Also known as
BadHost, LiteLLM MCP RCE
Severity
CRITICAL
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, artificial-intelligence, software, cloud-services, government
Target regions
Global, North America, Europe
Detection rules
9
Indicators of compromise
33
Updates
2026-08-27 · 2 updates · revalidated 2× · latest source

How CVE-2026-42271 works

CVE-2026-42271 is an OS command injection flaw in the LiteLLM (BerriAI) AI gateway MCP test endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) that lets an authenticated proxy user spawn arbitrary commands on the proxy host. CISA added it to the Known Exploited Vulnerabilities catalog on June 8, 2026. Horizon3.ai demonstrated chaining it with CVE-2026-48710 (the Starlette 'BadHost' Host-header authentication bypass) to reach fully unauthenticated remote code execution (combined CVSS 10.0).

CVE-2026-42271 is a command injection vulnerability (CWE-77 / CWE-78) affecting the BerriAI LiteLLM proxy/AI-gateway from version 1.74.2 up to but not including 1.83.7 (i.e., 1.74.2 through 1.83.6). Two endpoints used to preview an MCP (Model Context Protocol) server before saving its configuration — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the MCP stdio transport. When invoked with a stdio configuration, LiteLLM attempted to establish the connection, which spawned the attacker-supplied command as a subprocess on the proxy host with the privileges of the LiteLLM proxy process. The flaw therefore allowed any user holding a valid proxy API key, including low-privilege users, to achieve arbitrary OS command execution. NVD scores CVE-2026-42271 at CVSS 3.1 base 8.8 (vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

The LiteLLM advisory was published in early May 2026 and fixed in v1.83.7, which added authorization controls restricting the test endpoints to PROXY_ADMIN users and updated the Starlette dependency. CISA added CVE-2026-42271 to its Known Exploited Vulnerabilities (KEV) catalog on June 8, 2026 after evidence of active exploitation, and set a remediation deadline of June 22, 2026 for U.S. federal civilian executive branch (FCEB) agencies. No specific threat actor, campaign, or attribution was disclosed alongside the active-exploitation evidence.

The vulnerability becomes substantially more dangerous when chained with CVE-2026-48710 (CWE-444), the 'BadHost' Host-header validation bypass in the Starlette ASGI framework (affected versions 0.8.3 through 1.0.0, fixed in 1.0.1). In vulnerable Starlette, the HTTP Host request header is not validated before being used to reconstruct request.url. Because routing relies on the raw HTTP path while request.url is rebuilt from the Host header, a malformed header such as 'Host: target/allowpath?x=' makes request.url.path differ from the path actually requested, so path-based (allowlist / fail-closed) authentication middleware can be bypassed. Horizon3.ai disclosed (May 28, 2026) that this can be used to entirely sidestep the LiteLLM API-key requirement and reach the command-injection endpoints unauthenticated, transforming the bug into unauthenticated remote code execution with a combined CVSS of 10.0.

Post-exploitation, an attacker who reaches code execution on a LiteLLM host can access model-provider credentials, steal API keys and secrets stored by the proxy, and move laterally into connected AI infrastructure and downstream systems integrated with the gateway. BadHost is a framework-level flaw affecting FastAPI, vLLM, LiteLLM, Ray Serve, BentoML, MCP servers, Google ADK-Python, and any Python ASGI application that applies path-based auth middleware trusting request.url.path. Remediation: upgrade LiteLLM to >=1.83.7 and Starlette to >=1.0.1; if patching is not immediately possible, block the two /mcp-rest/test/* endpoints at a reverse proxy or API gateway, validate Host headers at a fronting proxy, restrict network access to trusted segments, and rotate proxy-stored credentials.

MITRE ATT&CK techniques used in TL-2026-0738

Collection

T1005 Data from Local System

Defense Evasion

T1036 Masquerading; T1211 Exploitation for Stealth

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Persistence

T1053.003 Scheduled Task/Job: Cron; T1098.004 Account Manipulation: SSH Authorized Keys

Execution

T1059 Command and Scripting Interpreter; T1059.004 Unix Shell; T1059.006 Python

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application

Lateral Movement

T1210 Exploitation of Remote Services

Credential Access

T1212 Exploitation for Credential Access; T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1552.001 Credentials In Files; T1552.005 Cloud Instance Metadata API

Impact

T1496 Resource Hijacking

defense-impairment

T1556 Modify Authentication Process

Reconnaissance

T1595 Active Scanning

Affected products and versions in CVE-2026-42271

  • BerriAI — LiteLLM
    Vulnerable versions: 1.74.2 through 1.83.6
    Fixed in: 1.83.7
  • Encode / Kludex — Starlette
    Vulnerable versions: 0.8.3 through 1.0.0
    Fixed in: 1.0.1

Remediation for CVE-2026-42271

Patches

  • LiteLLM v1.83.7-stable (restricts MCP test endpoints to PROXY_ADMIN role and updates Starlette)
  • Starlette v1.0.1 (ignores Host headers containing invalid characters per RFC 9112 3.2 / RFC 3986 3.2.2)

Immediate actions

  • Upgrade LiteLLM to v1.83.7 or later (BerriAI patched both the command injection and bumped the Starlette dependency)
  • Upgrade Starlette to v1.0.1 or later to close the CVE-2026-48710 BadHost Host-header bypass
  • If immediate patching is not possible, block POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list at the reverse proxy or API gateway
  • Rotate all model-provider credentials, API keys, and secrets stored by or reachable from the LiteLLM proxy

Workarounds

  • Block the /mcp-rest/test/* preview endpoints at the perimeter
  • Disable or gate the MCP server preview/test functionality where not required
  • Enforce Host-header validation at a reverse proxy as compensating control for unpatched Starlette

Longer-term hardening

  • Place a fronting reverse proxy (nginx, Caddy, Traefik) that validates the HTTP Host header against an allowlist before requests reach the ASGI app
  • Replace path-based auth middleware that trusts request.url.path with endpoint-level decorators (requires(), Depends(), Security()) or use scope['path'] instead of request.url.path
  • Restrict network access to AI-gateway management/test endpoints to trusted administrative segments only
  • Deploy EDR/behavioral monitoring on AI-gateway hosts to detect unexpected subprocess execution by the proxy process

CVEs associated with CVE-2026-42271

CVE-2026-42271, CVE-2026-48710

Weaknesses (CWE) in CVE-2026-42271

CWE-77, CWE-78, CWE-444

Timeline of CVE-2026-42271

  • BerriAI publishes GitHub Security Advisory GHSA-v4p8-mg3p-g94g and releases LiteLLM v1.83.7-stable, fixing CVE-2026-42271 by restricting the MCP test endpoints to PROXY_ADMIN users and updating the Starlette dependency. NVD publishes CVE-2026-42271 (CVSS 8.8).
  • Starlette v1.0.1 released, fixing CVE-2026-48710 BadHost by rejecting Host headers containing invalid characters per RFC 9112 3.2 / RFC 3986 3.2.2. Encode/Kludex publish GitHub Security Advisory GHSA-86qp-5c8j-p5mr.
  • CVE-2026-48710 ('BadHost') Starlette Host-header authentication bypass disclosed by X41 D-Sec and Nicolas Lamoureux, coordinated by OSTIF. NVD publishes the CVE (CVSS 6.5, CWE-444).
  • CSO Online and the CCB Belgium issue advisories warning that FastAPI/Starlette-based AI tools (FastAPI, vLLM, LiteLLM, Ray Serve, BentoML, MCP servers, Google ADK-Python) are exposed to the BadHost authentication bypass.
  • Horizon3.ai publishes research showing CVE-2026-42271 chained with CVE-2026-48710 to bypass authentication entirely and achieve unauthenticated remote code execution against LiteLLM (combined CVSS 10.0).
  • CISA adds CVE-2026-42271 to the Known Exploited Vulnerabilities (KEV) catalog citing evidence of active exploitation in the wild.
  • Help Net Security and The Hacker News report on active exploitation and the CISA KEV addition; SoCRadar and CSO Online publish analysis of the LiteLLM RCE and Starlette BadHost chain.
  • CISA-mandated remediation deadline for U.S. federal civilian executive branch (FCEB) agencies to patch CVE-2026-42271.
  • Microsoft publishes 'When AI infrastructure becomes the target,' documenting a coordinated, financially-motivated campaign that exploits the CVE-2026-42271/CVE-2026-48710 LiteLLM chain (alongside separate RAGFlow and Kestra CVEs) for credential harvesting, SSH/cron persistence with masquerading, and XMRig cryptomining.
  • Cyber Security News and GBHackers report the campaign's C2 infrastructure, DNS-rebinding domain (45.150.109.151.sslip.io), OAST callback domains, and XMRig mining-pool endpoint (auto.c3pool.org) tied to the CVE-2026-42271/CVE-2026-48710 LiteLLM exploitation chain, alongside a public PoC (CVE-2026-42271-PoC).

Update history for TL-2026-0738

Sources cited for CVE-2026-42271

Detection coverage for TL-2026-0738

As of 2026-08-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0738 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
33 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats