LiteLLM是LiteLLM团队开源的一个应用程序。 LiteLLM 1.18.10版本存在远程代码执行漏洞,该漏洞源于MCP server创建功能允许用户通过JSON配置指定任意命令和参数值,但未进行验证直接执行,可能导致攻击者运行任意操作系统命令,成功利用可导致远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | LiteLLM 1.18.10 contains a remote code execution caused by lack of validation of arbitrary command and args in MCP server creation, letting attackers execute OS commands remotely, exploit requires crafted JSON configuration. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-30623.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-61371 | Microsoft AVML 后置链接漏洞 | |
| CVE-2026-51380 | Tenda ac10 安全漏洞 | |
| CVE-2026-30618 | guo zebin Fay 安全漏洞 | |
| CVE-2025-65720 | Assaf Elovic GPT Researcher 安全漏洞 | |
| CVE-2026-26718 | xuxueli xxl-job-admin 安全漏洞 | |
| CVE-2026-26719 | xuxueli xxl-job-admin 安全漏洞 | |
| CVE-2026-36590 | EMQ NanoMQ 安全漏洞 | |
| CVE-2026-38974 | Jelmer Vernooij Dulwich 安全漏洞 |
No comments yet