Fetching from the wire…
Security2026-05-11 · source-backed
CVE-2026-30623 allows arbitrary command injection through crafted server configurations if your LiteLLM proxy exposes MCP endpoints. Patch is available. Update immediately and audit any MCP configs accepting user-provided command strings.
Each link below shares sources, entities, or timing with this story.
OX Security criticizes MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (OX Security criticizes MCP); both cover Anthropic, CVE, LiteLLM, MCP; overlapping topics (anthropic, arbitrary, audit, command, configuration).
Anthropic released MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Anthropic released MCP); both cover Anthropic, CVE, MCP; overlapping topics (anthropic, arbitrary, audit, command, injection).
Microsoft supports MCP / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Microsoft supports MCP); both cover CVE, LiteLLM, MCP; overlapping topics (command, litellm).
Microsoft supports MCP / Shared entities / What happened next / Tension
Linked by a graph relationship (Microsoft supports MCP); both cover Anthropic, CVE, MCP; picks up the Anthropic thread on 2026-07-23.
Microsoft supports MCP / Shared entities / Earlier coverage / Tension
Linked by a graph relationship (Microsoft supports MCP); both cover Anthropic, CVE, MCP; earlier Anthropic coverage from 2026-03-23.
Anthropic released MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Anthropic released MCP); both cover CVE, MCP, Update; overlapping topics (audit, endpoint).
Linked by a graph relationship (Anthropic released MCP); both cover CVE, MCP; overlapping topics (command, config, disclos, endpoint).
MCP uses Docker / Shared entities / What happened next
Linked by a graph relationship (MCP uses Docker); both cover Anthropic, CVE, MCP; picks up the Anthropic thread on 2026-08-21.