cbcvebase.
CVE-2026-30623
published 2026-07-15

CVE-2026-30623: LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a…

PriorityP276critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
5.00%
91.6th percentile
LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration specifying arbitrary command and args values. LiteLLM executes these values on the host without validation, enabling attackers to run arbitrary operating system commands. Successful exploitation may result in remote code execution with the privileges of the LiteLLM process.

Affected

3 ranges
VendorProductVersion rangeFixed in
ansible-automation-platform-26lightspeed-chatbot-rhel9
ansible-automation-platform-27lightspeed-chatbot-rhel9
lightspeed-corelightspeed-stack-rhel9

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for MCP server creation API calls in LiteLLM containing arbitrary `command` and `args` values in JSON configuration payloads, which may indicate exploitation attempts.
  • Alert on unexpected child processes spawned by the LiteLLM process, as successful exploitation results in OS command execution under the LiteLLM process privileges.
  • Inspect inbound JSON payloads to LiteLLM's MCP server creation endpoint for the presence of `command` and `args` fields containing shell commands or suspicious executables.
  • ·The vulnerability is specific to LiteLLM version 1.18.10; verify the exact version deployed before applying detections.
  • ·Red Hat packages exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 and rhoai/* are confirmed Not Affected; lightspeed-core and ansible-automation-platform packages remain Under Investigation.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.