Skip to finding
important · Edge devices

An exploited LiteLLM authentication fallback accepts fabricated bearer tokens for configured MCP tools.

Affects

LiteLLM, an AI-model gateway and proxy commonly deployed on Linux servers and in containers.

Failed key validation falls through OAuth2 passthrough to an empty authentication object, allowing the caller to list and invoke tools and connected services behind an exposed Streamable HTTP endpoint.

Detail and 2 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 8, 2026