Posts Tagged ‘LiteLLM’
LiteLLM MCP Authentication Bypass: Patch Now
A LiteLLM MCP authentication bypass, CVE-2026-59822 (CVSS 8.8), lets an attacker skip OAuth2 login entirely when connecting to Model Context Protocol servers through LiteLLM’s proxy, gaining whatever access an authenticated session would carry. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 2, the first MCP-related vulnerability ever listed there; WatchTowr reports…
Read More
