CVE
CVE-2026-35029
LiteLLM affected by privilege escalation via unrestricted proxy configuration endpoint
Exploitation IoCs 5
Domain chatgpt[.]com
Filename guardrail_endpoints.py
Filename pass_through_endpoints.py
Filename user_api_key_auth_mcp.py
SHA-256 sk-1234
MITRE ATT&CK TTPs 9
T1053.005 T1059.003 T1078 T1090 T1133 T1190 T1204.001 T1552 T1566
Scheduled Task
Execution
Windows Command Shell
Execution
Valid Accounts
Defense Evasion
Proxy
Command And Control
External Remote Services
Persistence
Exploit Public-Facing Application
Initial Access
Malicious Link
Execution
Unsecured Credentials
Credential Access
Phishing
Initial Access
Source Articles
Off Guard: Breaking LiteLLM from authentication bypass to cloud compromise
Multiple critical vulnerabilities were discovered in LiteLLM, a popular open-source LLM gateway, enabling authentication bypass, remote code execution, and cloud credential theft. CVE-2026-59822 allows unauthenticated access to MCP endpoints via a Bearer token bypass, while CVE-2026-59821 enables post-authentication root-level RCE through unsandboxed custom code guardrails. A default master key (sk-1234) is accepted by 9.6% of public instances, allowing attackers to achieve admin access and exploit these vulnerabilities. Additionally, pass-through endpoints can be abused to exfiltrate cloud metadata and IAM credentials, especially when combined with default or missing authentication.
wiz
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
A critical vulnerability named AgentForger in OpenAI's ChatGPT Workspace Agents could allow attackers to deploy rogue AI agents via a phishing link. The flaw, a cross-site request forgery (CSRF), enables automatic creation and execution of malicious agents within an authenticated user's session without further interaction. These agents can persist, execute tasks from emails, access enterprise data, and send phishing messages, effectively becoming autonomous insiders.
hacker-news Jul 24, 2026