# CVE-2026-42271: LiteLLM MCP Server Command Injection Under Active Exploitation, Chained with CVE-2026-48710 (Starlette BadHost) for Unauthenticated RCE

> CVE-2026-42271 is an OS command injection flaw in the LiteLLM (BerriAI) AI gateway MCP test endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) that lets an authenticated proxy user spawn arbitrary commands on the proxy host. CISA added it to the Known Exploited Vulnerabilities catalog on June 8, 2026. Horizon3.ai demonstrated chaining it with CVE-2026-48710 (the Starlette 'BadHost' Host-header authentication bypass) to reach fully unauthenticated remote code execution (combined CVSS 10.0).

- **Published:** 2026-06-09T00:00:00Z
- **Last reviewed:** 2026-08-27T13:25:16.363Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0738
- **ID:** TL-2026-0738
- **Severity:** CRITICAL (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 33 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-42271, CVE-2026-48710

## Description

CVE-2026-42271 is a command injection vulnerability (CWE-77 / CWE-78) affecting the BerriAI LiteLLM proxy/AI-gateway from version 1.74.2 up to but not including 1.83.7 (i.e., 1.74.2 through 1.83.6). Two endpoints used to preview an MCP (Model Context Protocol) server before saving its configuration — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the MCP stdio transport. When invoked with a stdio configuration, LiteLLM attempted to establish the connection, which spawned the attacker-supplied command as a subprocess on the proxy host with the privileges of the LiteLLM proxy process. The flaw therefore allowed any user holding a valid proxy API key, including low-privilege users, to achieve arbitrary OS command execution. NVD scores CVE-2026-42271 at CVSS 3.1 base 8.8 (vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

The LiteLLM advisory was published in early May 2026 and fixed in v1.83.7, which added authorization controls restricting the test endpoints to PROXY_ADMIN users and updated the Starlette dependency. CISA added CVE-2026-42271 to its Known Exploited Vulnerabilities (KEV) catalog on June 8, 2026 after evidence of active exploitation, and set a remediation deadline of June 22, 2026 for U.S. federal civilian executive branch (FCEB) agencies. No specific threat actor, campaign, or attribution was disclosed alongside the active-exploitation evidence.

The vulnerability becomes substantially more dangerous when chained with CVE-2026-48710 (CWE-444), the 'BadHost' Host-header validation bypass in the Starlette ASGI framework (affected versions 0.8.3 through 1.0.0, fixed in 1.0.1). In vulnerable Starlette, the HTTP Host request header is not validated before being used to reconstruct request.url. Because routing relies on the raw HTTP path while request.url is rebuilt from the Host header, a malformed header such as 'Host: target/allowpath?x=' makes request.url.path differ from the path actually requested, so path-based (allowlist / fail-closed) authentication middleware can be bypassed. Horizon3.ai disclosed (May 28, 2026) that this can be used to entirely sidestep the LiteLLM API-key requirement and reach the command-injection endpoints unauthenticated, transforming the bug into unauthenticated remote code execution with a combined CVSS of 10.0.

Post-exploitation, an attacker who reaches code execution on a LiteLLM host can access model-provider credentials, steal API keys and secrets stored by the proxy, and move laterally into connected AI infrastructure and downstream systems integrated with the gateway. BadHost is a framework-level flaw affecting FastAPI, vLLM, LiteLLM, Ray Serve, BentoML, MCP servers, Google ADK-Python, and any Python ASGI application that applies path-based auth middleware trusting request.url.path. Remediation: upgrade LiteLLM to >=1.83.7 and Starlette to >=1.0.1; if patching is not immediately possible, block the two /mcp-rest/test/* endpoints at a reverse proxy or API gateway, validate Host headers at a fronting proxy, restrict network access to trusted segments, and rotate proxy-stored credentials.

## MITRE ATT&CK

- T1595 Active Scanning
- T1190 Exploit Public-Facing Application
- T1133 External Remote Services
- T1059 Command and Scripting Interpreter
- T1059.004 Unix Shell
- T1059.006 Python
- T1211 Exploitation for Stealth
- T1556 Modify Authentication Process
- T1552 Unsecured Credentials
- T1552.001 Credentials In Files
- T1528 Steal Application Access Token
- T1212 Exploitation for Credential Access
- T1082 System Information Discovery
- T1210 Exploitation of Remote Services
- T1552.005 Cloud Instance Metadata API
- T1083 File and Directory Discovery
- T1005 Data from Local System
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1068 Exploitation for Privilege Escalation
- T1053.003 Scheduled Task/Job: Cron
- T1098.004 Account Manipulation: SSH Authorized Keys
- T1036 Masquerading
- T1496 Resource Hijacking

## Sources

- [LiteLLM vulnerability under active attack, CISA warns (CVE-2026-42271)](https://www.helpnetsecurity.com/2026/06/09/litellm-vulnerability-under-active-attack-cisa-warns-cve-2026-42271/)
- [LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE](https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html)
- [CVE-2026-42271: LiteLLM Unauthenticated RCE (chained with CVE-2026-48710)](https://horizon3.ai/attack-research/vulnerabilities/cve-2026-42271-chained-with-cve-2026-48710/)
- [BerriAI LiteLLM GitHub Security Advisory GHSA-v4p8-mg3p-g94g](https://github.com/BerriAI/litellm/security/advisories/GHSA-v4p8-mg3p-g94g)
- [LiteLLM v1.83.7-stable release (patch)](https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable)
- [CISA Known Exploited Vulnerabilities Catalog - CVE-2026-42271](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42271)
- [NVD - CVE-2026-42271](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-42271)
- [NVD - CVE-2026-48710](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-48710)
- [BadHost - CVE-2026-48710 Starlette Host-Header Auth Bypass](https://badhost.org/)
- [Disclosing the BADHOST Vulnerability in Starlette - OSTIF](https://ostif.org/disclosing-the-badhost-vulnerability-in-starlette/)
- [X41 D-Sec Advisory X41-2026-002 Starlette](https://www.x41-dsec.de/lab/advisories/x41-2026-002-starlette)
- [Starlette GitHub Security Advisory GHSA-86qp-5c8j-p5mr](https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr)
- [FastAPI-based AI tools exposed to authentication bypass by flaw in Starlette framework](https://www.csoonline.com/article/4177711/fastapi-based-ai-tools-exposed-to-authentication-bypass-by-flaw-in-starlette-framework.html)
- [CISA KEV Highlights LiteLLM RCE (CVE-2026-42271) & Check Point VPN Auth Bypass](https://socradar.io/blog/cisa-kev-litellm-cve-2026-42271-check-point-cve-2026-50751/)
- [CCB Belgium Advisory: Starlette / FastAPI authentication bypass](https://ccb.belgium.be/advisories/warning-vulnerability-starlette-framework-and-related-frameworks-fastapi-exposes)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0738
