What happened
Google Threat Intelligence Group's report 'Vulnerability Discovery and Exploitation Trends in the AI Era' (2026-10-01, hotly discussed in-window) confirms threat actors are actively exploiting newly-disclosed AI-stack vulnerabilities, naming LiteLLM CVE-2026-42271 (command injection in MCP server preview endpoints, fixed 1.83.7) and Langflow CVE-2026-5027 (path-traversal file write via the upload handler) among only a handful of High-Threat AI infrastructure flaws confirmed exploited in the wild. GTIG counted 2,076 AI-related CVEs from Jan 2025–Aug 2026 (over 1,500 in 2026 alone) and warned zero-day exploitation of AI infrastructure has not yet been seen but middleware weaponization is active.
Why it matters
This is direct in-the-window threat intelligence that AI gateways and workflow platforms are being actively compromised in the field, not just theoretically vulnerable. AI middleware commonly proxies to multiple foundation-model providers and stores those API keys in-process, so an RCE or arbitrary file write on LiteLLM/Langflow is a direct path to model-provider credential theft and downstream AI workload compromise — patch-lag discipline on these exposed services is the immediate defensive action.
Attack vector
LiteLLM: low-privilege API keys can drive the MCP-server test endpoints to start an arbitrary stdio subprocess (command injection, CWE-77/78), giving host takeover and API-credential theft — CISA KEV-listed since June 8, 2026. Langflow: in-effect path-traversal file write in the multipart upload handler lets attackers drop cron jobs or SSH keys (CVE-2026-5027, exploited in the wild per GTIG).
Affected systems
BerriAI LiteLLM 1.74.2 to <1.83.7 (MCP server preview endpoints POST /mcp-rest/test/connection and /mcp-rest/test/tools/list); Langflow <1.9.0 (POST /api/v2/files upload handler)
Mitigation
LiteLLM fixed in 1.83.7 (test endpoints now require PROXY_ADMIN role; affects Red Hat OpenShift AI builds 2.25<2.25.8, 3.3<3.3.4, 3.4); Langflow fixed in 1.9.0. Patch immediately; restrict AI gateway/workflow hosts from public exposure; treat any reachable AI middleware as hosting upstream model-provider credentials