Vulnerability intelligence
CVE-2026-42271
Auth bypass → admin privilege escalation → Python sandbox escape via unfiltered exec() → MCP callback injection. The open-source AI gateway used to route requests between Claude, GPT, and Gemini had a kill chain from viewer to root. Patched in v1.83.14.
FastAPI
2026
What WebPulse reported · 2 analyses
LiteLLM AI Gateway: CVSS 9.9. Four Chained Vulnerabilities Let a Low-Privilege User Hijack Claude Code Responses.
Auth bypass → admin privilege escalation → Python sandbox escape via unfiltered exec() → MCP callback injection. The open-source AI gateway used to route reques
June 16, 2026
CVE-2026-48710 'BadHost': The Vulnerability That Hit FastAPI, vLLM, LiteLLM, and 325 Million Weekly Downloads.
A malformed Host header bypasses authentication in Starlette — the ASGI framework underneath FastAPI and most of Python's AI agent infrastructure. Modern framew
June 14, 2026
Related vulnerabilities