ID:13077 - Exploit for OS Command Injection in LiteLLM - CVE-2026-42271

 
Main Vulnerability Database Exploits ID:13077 - Exploit for OS Command Injection in LiteLLM - CVE-2026-42271

ID:13077 - Exploit for OS Command Injection in LiteLLM - CVE-2026-42271

Published: September 28, 2026


Vulnerability identifier: #VU128068
Vulnerability risk: Medium
CVE-ID: CVE-2026-42271
CWE-ID: CWE-78
Exploitation vector: Remote access
Vulnerable software:
LiteLLM
Python for Scientific Computing

Link to public exploit:


Vulnerability description

The vulnerability allows a remote user to execute arbitrary commands on the host.

The vulnerability exists due to improper neutralization of special elements used in an os command in the MCP stdio test endpoints when processing a full server configuration for stdio transport. A remote user can submit a specially crafted request containing command, args, and env fields to execute arbitrary commands on the host.

The issue affects POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list, and the supplied command is spawned as a subprocess with the privileges of the proxy process.


Remediation

Install security update from vendor's website.