LiteLLM Flaw Could Expose Enterprise AI Gateways
On June 9, CISA added CVE-2026-42271 to its Known Exploited Vulnerabilities catalog, giving federal agencies 13 days to patch a command injection flaw in LiteLLM, one of the most widely deployed open-source AI gateways in enterprise production. The affected endpoints — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — are Model Context Protocol interfaces: the layer where…
