Executive brief
LiteLLM is a popular library for managing interactions with large language models and API proxies. The MCP (Model Context Protocol) Proxy component has a flaw in its authentication mechanism that allows attackers to bypass security checks by providing any arbitrary token, gaining unauthorized access to backend MCP servers. An attacker can leverage this to execute sensitive tools, extract data, or potentially achieve remote code execution without valid credentials.
Technical details
The vulnerability is a classic exception-swallowing authentication bypass in the process_mcp_request method. When the user_api_key_auth validation function raises a 401 or 403 HTTPException due to invalid or missing credentials, the code catches and discards the exception, then instantiates a default UserAPIKeyAuth() object that permits access. The flaw lies in litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py and affects the authorization flow in get_allowed_mcp_servers. Attack vector is network-based with no authentication or user interaction required. An attacker simply sends a JSON-RPC request with any arbitrary Bearer token to the MCP endpoint (e.g., POST /mock_server/mcp) and gains full access to configured MCP servers with allow_all_keys: true, enabling tool enumeration, data extraction, or RCE depending on available tools. The issue was patched in version 1.84.0.
Affected products
- BerriAI LiteLLM < 1.84.0
Timeline
- 2026-06-21: disclosed
- 2026-06-21: patched: Fixed in version 1.84.0
- 2026-09-10: advisory: GitHub Security Advisory reviewed