CISA flags actively exploited LiteLLM AI gateway flaw for federal fix
The command-injection bug, added to CISA's exploited-vulnerabilities catalog on June 8, can be chained for unauthenticated remote code execution and AI credential theft.
The US Cybersecurity and Infrastructure Security Agency (CISA) confirmed active exploitation of a command-injection flaw in the LiteLLM AI proxy gateway, adding CVE-2026-42271 to its Known Exploited Vulnerabilities catalog on June 8, 2026, the agency disclosed. The bug, rated CVSS 8.7, sits in BerriAI's widely deployed LiteLLM software, which routes requests across multiple AI model providers.
The flaw lives in two MCP server test endpoints that accept full server configuration, including command, arguments and environment fields, opening the door to injecting operating-system commands.
Researchers at security firm Horizon3.ai chained CVE-2026-42271 with a second bug, CVE-2026-48710 (CVSS 6.5) — a "BadHost" host-header validation bypass in the Starlette ASGI framework — to defeat authentication and reach unauthenticated remote code execution. By their account, a successful attack allows arbitrary command execution on the LiteLLM host, access to AI model-provider credentials, exfiltration of API keys, and lateral movement into connected AI infrastructure.
The severity rests on that chain and on the researchers' demonstration rather than on observed mass attacks; CISA's catalog confirms exploitation but does not quantify its scale. The risk is also conditional on exposure — instances reachable over the network with the test endpoints enabled are the ones at issue.
CISA directed federal civilian agencies to remediate CVE-2026-42271 by June 22, 2026, per its catalog entry, and recommended upgrading LiteLLM to a patched release or blocking the affected MCP test endpoints and restricting network access. The same alert added a second, unrelated vulnerability to the catalog. The incident is an early marker of attackers probing the AI tooling layer itself — the gateways and proxies that hold the credentials to everything behind them.
Founder and Chief Editor of Data Phoenix — a San Francisco Bay Area media and education platform focused on AI and Data.
More news

AWS releases six open-source Hugging Face deployment skills for SageMaker

Google Research releases MilleMiglia logistics benchmark generator

AWS launches AgentCore Runtime V2 with elastic memory and snapshot starts
