PoC Archive PoC Archive

tag

Subprocess

  • CVE-2026-42271 web HIGH 8.7 KEV EPSS 83%

    Authenticated Command Injection in LiteLLM MCP Test Endpoints (CVE-2026-42271)

    CVE-2026-42271 is a command injection vulnerability in BerriAI LiteLLM's MCP preview/test endpoints — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list. These endpoints accept a full MCP server configuration in the request body, including…

    Patched 2026-07-01