CVE
CVE-2026-42271
- First Reported
- Sep 30, 2026
- Latest Reported
- Sep 30, 2026
Reported Context (1)
- CVE-2026-42271 (BerriAI LiteLLM): Command injection in Model Context Protocol (MCP) server preview endpoints (POST /mcp-rest/test/connection), resulting in host takeover and API credential theft. Google Finds AI Is Changing Vulnerability Discovery and Exploitation Trends
CVE (3)
Malware (2)
MITRE ATT&CK (1)
Vendors (5)
Products (12)
Tools (3)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.