سيبرانا

قاعدة الثغرات (CVE)

CVE-2026-59822

مصادقة غير سليمة في نقطة نهاية MCP بـ LiteLLM

عاليةمُستغلة فعليًاKEVالتصحيح متوفر: غير متوفر بعد

نقطة نهاية MCP Streamable HTTP تقبل أي رمز Bearer عشوائي لإنشاء جلسة MCP مصادَق عليها — ثغرة في طبقة ربط الوكلاء بالأدوات، وثالث ثغرة LiteLLM المستغلة.

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.

المنتجات المتأثرة

Productالإصدارات المتأثرةتم الإصلاح في
LiteLLM

التغطية على سيبرانا