important · Edge devices
An exploited LiteLLM authentication fallback accepts fabricated bearer tokens for configured MCP tools.
Affects
LiteLLM, an AI-model gateway and proxy commonly deployed on Linux servers and in containers.
Failed key validation falls through OAuth2 passthrough to an empty authentication object, allowing the caller to list and invoke tools and connected services behind an exposed Streamable HTTP endpoint.
Detail and 2 sources
CISA has determined that the flaw is under active exploitation.