LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
Auth bypass lets attackers use MCP tools and reach connected services without a valid LiteLLM key.

3 CRIT · 5 HIGH · 1 MED · 1 LOW · 2 INFO · THREAT RED · 12 items · Generated in 222s
Auth bypass lets attackers use MCP tools and reach connected services without a valid LiteLLM key.
A shared chat payload can use a victim admin session to create a server-side tool and achieve remote code execution.
Authenticated users can write files outside the skill directory and possibly gain code execution.
Anyone on the network can invoke MCP tools and access or modify Dynatrace data using the server's credentials.
Users with terminal access may reach unintended backend paths using proxy credentials and user headers.
Startup failure can disable policy checks, letting restricted AWS operations run without enforcement until restart.
Template injection can create a persistent workflow that exfiltrates event data to attacker-controlled destinations after the session ends.
Privileged users could make LiteLLM read local files, exposing secrets or config from the host.
Reports an AI platform attack and highlights defensive lessons, but gives no actionable vulnerability details.
Suggests AI-assisted bug discovery has not yet translated into broad real-world exploitation.
This is malware news affecting developer endpoints, but the item shows no direct AI security flaw or exploitable AI issue.
A model-induced malicious package install led to real org compromises, showing AI output can trigger supply-chain attacks.