Executive brief
LiteLLM is a tool used to manage and interface with various AI models. A security flaw in its testing interface allowed any authenticated user to execute arbitrary system commands on the server hosting the application. This could lead to a complete system takeover, unauthorized access to sensitive AI configurations, or data theft by anyone with a basic API key.
Technical details
LiteLLM is vulnerable to OS command injection in the `POST /mcp-rest/test/connection` and `POST /mcp-rest/test/tools/list` endpoints. These endpoints, used for previewing Model Context Protocol (MCP) server configurations, accepted `command`, `args`, and `env` fields in the request body. When processed, the application spawned these inputs as subprocesses on the host using the stdio transport. The vulnerability was exacerbated by a lack of role-based access control (RBAC); any user with a valid proxy API key could access these endpoints regardless of their privilege level. Attackers can achieve full remote code execution (RCE) on the proxy host. The issue is fixed in version 1.83.7 by enforcing the PROXY_ADMIN role for these endpoints.
Affected products
- BerriAI litellm >= 1.74.2, < 1.83.7
Timeline
- 2026-04-19: patched: Version 1.83.7 released
- 2026-04-21: disclosed
- 2026-04-25: advisory