Threat reportVulnerabilityTL-2026-0738
CVE-2026-42271: LiteLLM MCP Server Command Injection Under Active Exploitation, Chained with CVE-2026-48710 (Starlette BadHost) for Unauthenticated RCE
CVE-2026-42271 (TL-2026-0738), also tracked as BadHost, is a critical-severity software vulnerability scored CVSS 8.8, first published 2026-06-09 and last reviewed 2026-08-27. It has no confirmed attribution, affects BerriAI LiteLLM, references 2 CVEs (CVE-2026-42271, CVE-2026-48710), maps to 24 MITRE ATT&CK techniques (T1005, T1036, T1041), and is covered by 9 detection rules and 33 indicators of compromise.
- CVSS
- 8.8/10Critical
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 24MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 33Indicators of compromise
Key facts for TL-2026-0738
- Threat ID
- TL-2026-0738
- Also known as
- BadHost, LiteLLM MCP RCE
- Severity
- CRITICAL
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, artificial-intelligence, software, cloud-services, government
- Target regions
- Global, North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 33
- Updates
- 2026-08-27 · 2 updates · revalidated 2× · latest source
How CVE-2026-42271 works
CVE-2026-42271 is an OS command injection flaw in the LiteLLM (BerriAI) AI gateway MCP test endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) that lets an authenticated proxy user spawn arbitrary commands on the proxy host. CISA added it to the Known Exploited Vulnerabilities catalog on June 8, 2026. Horizon3.ai demonstrated chaining it with CVE-2026-48710 (the Starlette 'BadHost' Host-header authentication bypass) to reach fully unauthenticated remote code execution (combined CVSS 10.0).
CVE-2026-42271 is a command injection vulnerability (CWE-77 / CWE-78) affecting the BerriAI LiteLLM proxy/AI-gateway from version 1.74.2 up to but not including 1.83.7 (i.e., 1.74.2 through 1.83.6). Two endpoints used to preview an MCP (Model Context Protocol) server before saving its configuration — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the MCP stdio transport. When invoked with a stdio configuration, LiteLLM attempted to establish the connection, which spawned the attacker-supplied command as a subprocess on the proxy host with the privileges of the LiteLLM proxy process. The flaw therefore allowed any user holding a valid proxy API key, including low-privilege users, to achieve arbitrary OS command execution. NVD scores CVE-2026-42271 at CVSS 3.1 base 8.8 (vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
The LiteLLM advisory was published in early May 2026 and fixed in v1.83.7, which added authorization controls restricting the test endpoints to PROXY_ADMIN users and updated the Starlette dependency. CISA added CVE-2026-42271 to its Known Exploited Vulnerabilities (KEV) catalog on June 8, 2026 after evidence of active exploitation, and set a remediation deadline of June 22, 2026 for U.S. federal civilian executive branch (FCEB) agencies. No specific threat actor, campaign, or attribution was disclosed alongside the active-exploitation evidence.
The vulnerability becomes substantially more dangerous when chained with CVE-2026-48710 (CWE-444), the 'BadHost' Host-header validation bypass in the Starlette ASGI framework (affected versions 0.8.3 through 1.0.0, fixed in 1.0.1). In vulnerable Starlette, the HTTP Host request header is not validated before being used to reconstruct request.url. Because routing relies on the raw HTTP path while request.url is rebuilt from the Host header, a malformed header such as 'Host: target/allowpath?x=' makes request.url.path differ from the path actually requested, so path-based (allowlist / fail-closed) authentication middleware can be bypassed. Horizon3.ai disclosed (May 28, 2026) that this can be used to entirely sidestep the LiteLLM API-key requirement and reach the command-injection endpoints unauthenticated, transforming the bug into unauthenticated remote code execution with a combined CVSS of 10.0.
Post-exploitation, an attacker who reaches code execution on a LiteLLM host can access model-provider credentials, steal API keys and secrets stored by the proxy, and move laterally into connected AI infrastructure and downstream systems integrated with the gateway. BadHost is a framework-level flaw affecting FastAPI, vLLM, LiteLLM, Ray Serve, BentoML, MCP servers, Google ADK-Python, and any Python ASGI application that applies path-based auth middleware trusting request.url.path. Remediation: upgrade LiteLLM to >=1.83.7 and Starlette to >=1.0.1; if patching is not immediately possible, block the two /mcp-rest/test/* endpoints at a reverse proxy or API gateway, validate Host headers at a fronting proxy, restrict network access to trusted segments, and rotate proxy-stored credentials.
MITRE ATT&CK techniques used in TL-2026-0738
Collection
Defense Evasion
T1036 Masquerading; T1211 Exploitation for Stealth
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Persistence
T1053.003 Scheduled Task/Job: Cron; T1098.004 Account Manipulation: SSH Authorized Keys
Execution
T1059 Command and Scripting Interpreter; T1059.004 Unix Shell; T1059.006 Python
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services
Credential Access
T1212 Exploitation for Credential Access; T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1552.001 Credentials In Files; T1552.005 Cloud Instance Metadata API
Impact
defense-impairment
T1556 Modify Authentication Process
Reconnaissance
Affected products and versions in CVE-2026-42271
- BerriAI — LiteLLM
Vulnerable versions: 1.74.2 through 1.83.6
Fixed in: 1.83.7 - Encode / Kludex — Starlette
Vulnerable versions: 0.8.3 through 1.0.0
Fixed in: 1.0.1
Remediation for CVE-2026-42271
Patches
- LiteLLM v1.83.7-stable (restricts MCP test endpoints to PROXY_ADMIN role and updates Starlette)
- Starlette v1.0.1 (ignores Host headers containing invalid characters per RFC 9112 3.2 / RFC 3986 3.2.2)
Immediate actions
- Upgrade LiteLLM to v1.83.7 or later (BerriAI patched both the command injection and bumped the Starlette dependency)
- Upgrade Starlette to v1.0.1 or later to close the CVE-2026-48710 BadHost Host-header bypass
- If immediate patching is not possible, block POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list at the reverse proxy or API gateway
- Rotate all model-provider credentials, API keys, and secrets stored by or reachable from the LiteLLM proxy
Workarounds
- Block the /mcp-rest/test/* preview endpoints at the perimeter
- Disable or gate the MCP server preview/test functionality where not required
- Enforce Host-header validation at a reverse proxy as compensating control for unpatched Starlette
Longer-term hardening
- Place a fronting reverse proxy (nginx, Caddy, Traefik) that validates the HTTP Host header against an allowlist before requests reach the ASGI app
- Replace path-based auth middleware that trusts request.url.path with endpoint-level decorators (requires(), Depends(), Security()) or use scope['path'] instead of request.url.path
- Restrict network access to AI-gateway management/test endpoints to trusted administrative segments only
- Deploy EDR/behavioral monitoring on AI-gateway hosts to detect unexpected subprocess execution by the proxy process
CVEs associated with CVE-2026-42271
Weaknesses (CWE) in CVE-2026-42271
Timeline of CVE-2026-42271
- BerriAI publishes GitHub Security Advisory GHSA-v4p8-mg3p-g94g and releases LiteLLM v1.83.7-stable, fixing CVE-2026-42271 by restricting the MCP test endpoints to PROXY_ADMIN users and updating the Starlette dependency. NVD publishes CVE-2026-42271 (CVSS 8.8).
- Starlette v1.0.1 released, fixing CVE-2026-48710 BadHost by rejecting Host headers containing invalid characters per RFC 9112 3.2 / RFC 3986 3.2.2. Encode/Kludex publish GitHub Security Advisory GHSA-86qp-5c8j-p5mr.
- CVE-2026-48710 ('BadHost') Starlette Host-header authentication bypass disclosed by X41 D-Sec and Nicolas Lamoureux, coordinated by OSTIF. NVD publishes the CVE (CVSS 6.5, CWE-444).
- CSO Online and the CCB Belgium issue advisories warning that FastAPI/Starlette-based AI tools (FastAPI, vLLM, LiteLLM, Ray Serve, BentoML, MCP servers, Google ADK-Python) are exposed to the BadHost authentication bypass.
- Horizon3.ai publishes research showing CVE-2026-42271 chained with CVE-2026-48710 to bypass authentication entirely and achieve unauthenticated remote code execution against LiteLLM (combined CVSS 10.0).
- CISA adds CVE-2026-42271 to the Known Exploited Vulnerabilities (KEV) catalog citing evidence of active exploitation in the wild.
- Help Net Security and The Hacker News report on active exploitation and the CISA KEV addition; SoCRadar and CSO Online publish analysis of the LiteLLM RCE and Starlette BadHost chain.
- CISA-mandated remediation deadline for U.S. federal civilian executive branch (FCEB) agencies to patch CVE-2026-42271.
- Microsoft publishes 'When AI infrastructure becomes the target,' documenting a coordinated, financially-motivated campaign that exploits the CVE-2026-42271/CVE-2026-48710 LiteLLM chain (alongside separate RAGFlow and Kestra CVEs) for credential harvesting, SSH/cron persistence with masquerading, and XMRig cryptomining.
- Cyber Security News and GBHackers report the campaign's C2 infrastructure, DNS-rebinding domain (45.150.109.151.sslip.io), OAST callback domains, and XMRig mining-pool endpoint (auto.c3pool.org) tied to the CVE-2026-42271/CVE-2026-48710 LiteLLM exploitation chain, alongside a public PoC (CVE-2026-42271-PoC).
Update history for TL-2026-0738
- 2026-08-27 — Hackers Exploit AI Infrastructure (LiteLLM, RAGFlow, Kestra) to Steal API Keys, Gain Persistence, and Mine Cryptocurrency: What changed No field escalations — severity (CRITICAL), exploitability (ACTIVE), status (ACTIVE), and attribution (Unknown/LOW) are unchanged; this update deepens evidence rather than escalating classification. New indicators (10) 6 new ne
- 2026-08-27 — Coordinated Campaign Exploits LiteLLM, RAGFlow, and Kestra AI Gateways for Credential Theft, Persistence, and Cryptomining: What changed Attribution confidence NONE → LOW and motivation UNKNOWN → FINANCIAL: Microsoft (Aug 26, 2026) confirms the CVE-2026-42271/CVE-2026-48710 LiteLLM exploit chain is being used in a coordinated, opportunistic campaign targeting AI
Sources cited for CVE-2026-42271
- LiteLLM vulnerability under active attack, CISA warns (CVE-2026-42271)
- LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE
- CVE-2026-42271: LiteLLM Unauthenticated RCE (chained with CVE-2026-48710)
- BerriAI LiteLLM GitHub Security Advisory GHSA-v4p8-mg3p-g94g
- LiteLLM v1.83.7-stable release (patch)
- CISA Known Exploited Vulnerabilities Catalog - CVE-2026-42271
- NVD - CVE-2026-42271
- NVD - CVE-2026-48710
- BadHost - CVE-2026-48710 Starlette Host-Header Auth Bypass
- Disclosing the BADHOST Vulnerability in Starlette - OSTIF
- X41 D-Sec Advisory X41-2026-002 Starlette
- Starlette GitHub Security Advisory GHSA-86qp-5c8j-p5mr
- FastAPI-based AI tools exposed to authentication bypass by flaw in Starlette framework
- CISA KEV Highlights LiteLLM RCE (CVE-2026-42271) & Check Point VPN Auth Bypass
- CCB Belgium Advisory: Starlette / FastAPI authentication bypass
Detection coverage for TL-2026-0738
As of 2026-08-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0738 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.