Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-30623

Опубликовано: 15 июл. 2026
Источник: redhat
CVSS3: 8.8

Описание

LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration specifying arbitrary command and args values. LiteLLM executes these values on the host without validation, enabling attackers to run arbitrary operating system commands. Successful exploitation may result in remote code execution with the privileges of the LiteLLM process.

A flaw was found in LiteLLM. This vulnerability allows a remote attacker to execute arbitrary operating system commands on the host where LiteLLM is running. This is possible because the application's MCP server creation functionality processes JSON configurations that can include unvalidated command and argument values. Successful exploitation could lead to a complete compromise of the affected system.

Отчет

This flaw allows an attacker who already possesses a valid LiteLLM Proxy API key to execute arbitrary operating system commands on the host running LiteLLM, via its MCP server creation and management functionality (NewMCPServerRequest/UpdateMCPServerRequest, and the /mcp-rest/test/* preview endpoints), which pass a user-supplied 'command' value to a subprocess without validation. Per the upstream advisory, exploitation requires authentication -- it is not reachable by a fully unauthenticated attacker -- but no further privilege beyond a working API key is needed to reach the vulnerable code path. Successful exploitation can result in complete compromise of the host running the LiteLLM process.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Not affected
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-chatbot-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/lightspeed-chatbot-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-llama-stack-core-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mlflow-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2501202litellm: LiteLLM: Remote code execution via unvalidated MCP server configuration

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
30 дней назад

LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration specifying arbitrary command and args values. LiteLLM executes these values on the host without validation, enabling attackers to run arbitrary operating system commands. Successful exploitation may result in remote code execution with the privileges of the LiteLLM process.

CVSS3: 9.8
github
30 дней назад

LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration specifying arbitrary command and args values. LiteLLM executes these values on the host without validation, enabling attackers to run arbitrary operating system commands. Successful exploitation may result in remote code execution with the privileges of the LiteLLM process.

8.8 High

CVSS3