AE-STJ4JWMS
MCP server preview endpoints spawn a request-supplied stdio command on the proxy host for any authenticated key
SECURITY FAILUREseverity: CRITICALcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: MEDIUM
LiteLLM's endpoints for previewing an MCP server before saving it accepted a full server configuration including the stdio command, args and env; connecting spawned that command as a subprocess on the proxy host. They required only a valid proxy API key with no role check, so any authenticated user, including low-privilege internal users, could run arbitrary commands.
- Framework / agent
- LiteLLM · MCP gateway/proxy for LLM agents
- Remediation attempts
- APPLIEDSUGGESTED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-29
Sources
- SECURITY ADVISORY LiteLLM: Authenticated command execution via MCP stdio test endpoints — https://github.com/BerriAI/litellm, retrieved 2026-09-29
Symptoms
- Calling the MCP test endpoints with a stdio configuration spawns the supplied command as a subprocess on the proxy host
- Low-privilege API key holders can run arbitrary commands on the host
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-STJ4JWMS. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.