CVE-2026-30623
published 2026-07-15CVE-2026-30623: LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a…
PriorityP276critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
5.00%
91.6th percentile
LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration specifying arbitrary command and args values. LiteLLM executes these values on the host without validation, enabling attackers to run arbitrary operating system commands. Successful exploitation may result in remote code execution with the privileges of the LiteLLM process.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-26 | lightspeed-chatbot-rhel9 | — | — |
| ansible-automation-platform-27 | lightspeed-chatbot-rhel9 | — | — |
| lightspeed-core | lightspeed-stack-rhel9 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for MCP server creation API calls in LiteLLM containing arbitrary `command` and `args` values in JSON configuration payloads, which may indicate exploitation attempts. ↗
- →Alert on unexpected child processes spawned by the LiteLLM process, as successful exploitation results in OS command execution under the LiteLLM process privileges. ↗
- →Inspect inbound JSON payloads to LiteLLM's MCP server creation endpoint for the presence of `command` and `args` fields containing shell commands or suspicious executables. ↗
- ·The vulnerability is specific to LiteLLM version 1.18.10; verify the exact version deployed before applying detections. ↗
- ·Red Hat packages exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 and rhoai/* are confirmed Not Affected; lightspeed-core and ansible-automation-platform packages remain Under Investigation. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality.
ghsa_unreviewed·2026-07-16
CVE-2026-30623 [CRITICAL] CWE-77 LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality.
LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration specifying arbitrary command and args values. LiteLLM executes these values on the host without validation, enabling attackers to run arbitrary operating system commands. Successful exploitation may result in remote code execution with the privileges of the LiteLLM process.
VulDB
BerriAI LiteLLM 1.18.10 MCP Server Creation command/args os command injection
vuldb·2026-07-16
CVE-2026-30623 [CRITICAL] BerriAI LiteLLM 1.18.10 MCP Server Creation command/args os command injection
A vulnerability was found in BerriAI LiteLLM 1.18.10 and classified as critical. This impacts an unknown function of the component MCP Server Creation. Executing a manipulation of the argument command/args can lead to os command injection.
This vulnerability is tracked as CVE-2026-30623. The attack can be launched remotely. No exploit exists.
Red Hat
litellm: LiteLLM: Remote code execution via unvalidated MCP server configuration
vendor_redhat·2026-07-15·CVSS 9.8
CVE-2026-30623 [CRITICAL] CWE-78 litellm: LiteLLM: Remote code execution via unvalidated MCP server configuration
litellm: LiteLLM: Remote code execution via unvalidated MCP server configuration
LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration specifying arbitrary command and args values. LiteLLM executes these values on the host without validation, enabling attackers to run arbitrary operating system commands. Successful exploitation may result in remote code execution with the privileges of the LiteLLM process.
A flaw was found in LiteLLM. This vulnerability allows a remote attacker to execute arbitrary operating system commands on the host where LiteLLM is running. This is possible because the application's MCP server creation functionality processes JSON configurations
No detection rules found.
Nuclei
LiteLLM 1.18.10 - Command Injection
nuclei·CVSS 9.8
CVE-2026-30623 [CRITICAL] LiteLLM 1.18.10 - Command Injection
LiteLLM 1.18.10 - Command Injection
LiteLLM 1.18.10 contains a remote code execution caused by lack of validation of arbitrary command and args in MCP server creation, letting attackers execute OS commands remotely, exploit requires crafted JSON configuration.
Template:
id: CVE-2026-30623
info:
name: LiteLLM 1.18.10 - Command Injection
author: leeseungsu
severity: high
description: |
LiteLLM 1.18.10 contains a remote code execution caused by lack of validation of arbitrary command and args in MCP server creation, letting attackers execute OS commands remotely, exploit requires crafted JSON configuration.
impact: |
Attackers can execute arbitrary OS commands remotely with LiteLLM process privileges, potentially compromising the host system.
remediation: |
Update to the latest version of
Bugzilla
CVE-2026-30623 litellm: LiteLLM: Remote code execution via unvalidated MCP server configuration
bugzilla·2026-07-15·CVSS 9.8
CVE-2026-30623 [CRITICAL] CVE-2026-30623 litellm: LiteLLM: Remote code execution via unvalidated MCP server configuration
CVE-2026-30623 litellm: LiteLLM: Remote code execution via unvalidated MCP server configuration
LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration specifying arbitrary command and args values. LiteLLM executes these values on the host without validation, enabling attackers to run arbitrary operating system commands. Successful exploitation may result in remote code execution with the privileges of the LiteLLM process.
Hackernews
Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain
blogs_hackernews·2026-04-20·CVSS 8.0
CVE-2025-65720 [HIGH] Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain
Cybersecurity researchers have discovered a critical "by design" weakness in the Model Context Protocol's ( MCP ) architecture that could pave the way for remote code execution and have a cascading effect on the artificial intelligence (AI) supply chain.
"This flaw enables Arbitrary Command Execution (RCE) on any system running a vulnerable MCP implementation, granting attackers direct access to sensitive user data, internal databases, API keys, and chat histories," OX Security researchers Moshe Siman Tov Bustan, Mustafa Naamnih, Nir Zadok, and Roni
2026-07-15
Published