
Or Weis
When the AI Gateway Becomes the Blast Radius: Lessons from the LiteLLM MCP RCE Chain
The LiteLLM CVE-2026-42271 and Starlette BadHost CVE-2026-48710 chain turned authenticated command injection into unauthenticated RCE. The deeper lesson: AI gateways hold model credentials, route sensitive traffic, and expose MCP utility endpoints — and need action-time authorization, not flat API keys.






