Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-30623: LiteLLM 1.18.10 MCP Server Creation Allows Malicious Code Execution
CVE-2026-30623
CVE-2026-30623
Summary
A security issue exists in LiteLLM 1.18.10 that could allow an attacker to execute malicious code on your server with the same permissions as the LiteLLM process. This can happen if an attacker is able to configure a LiteLLM MCP server with malicious code. To protect your server, update LiteLLM to the latest version and ensure you only allow trusted users to configure MCP servers.
Original title
LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration specifying arbitrar...
Original description
LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration specifying arbitrary command and args values. LiteLLM executes these values on the host without validation, enabling attackers to run arbitrary operating system commands. Successful exploitation may result in remote code execution with the privileges of the LiteLLM process.
Vulnerability type
CWE-77
Command Injection
Published: 15 Jul 2026 · Updated: 17 Jul 2026 · First seen: 15 Jul 2026