CVE-2026-42271
BerriAI LiteLLM Command Injection Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 8.7
- EPSS
- 75.0% 백분위 99.4% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2026.06.22
- 공개일
- 2026.05.08
CISA KEV에 등록된 실제 악용 확인 취약점
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a subprocess on the proxy host with the privileges of the proxy process. The endpoints we...
공급사 BerriAI
제품 LiteLLM
영향 버전 >= 1.74.2, < 1.83.7, >= 1.74.2 < 1.83.7
수정 버전 1.83.7
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
조치 기한: 2026.06.22CVSS 벡터 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE CWE-77, CWE-78
KEV 등록일 2026.06.08
랜섬웨어 캠페인 사용 미확인
CISA 비고 This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://github.com/BerriAI/litellm/security/advisories/GHSA-v4p8-mg3p-g94g ; https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable ; https://nvd.nist.gov/vuln/detail/CVE-2026-42271
EPSS 데이터 기준일 2026.06.27