MCP Python SDK maintainers rated a flaw that let a connected server choose where OAuth secrets were sent High, at 7.5. For its two machine-to-machine providers, upgrading changes nothing until the client names the issuer it expects.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+15
- Incentives30
- Confidence50
NVD logged CVEs for four MCP servers in about 35 hours, each because every tool it exposes needs no authentication. A fifth MCP flaw, LiteLLM's authentication bypass, is already on CISA's exploited-vulnerabilities list.
Reality
- Evidence62
- Adoption58
- Hype gap−6
- Incentives45
- Confidence52
LiteLLM's standalone Rust path added 0.7 ms of p99 latency against 257.7 ms for its Python proxy in July 22 benchmark artifacts reviewed on dev.to. Logging, persistence and spend tracking were off for the run, so the gap measures forwarding alone.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence40
LiteLLM launched Lens on September 30, a tool that uses AI agents to find recurring failures across agent traces sent through its model gateway. Customers host the analyzer and its databases, and the 200,000-trace volume CTO Ishaan Jaffer cites is a future target Lens has not been measured against.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+25
- Incentives60
- Confidence40
Google's threat intelligence group counts 18 exploited flaws a month in 2026, up from 10.5 in 2025, while zero-days rose only from eight to 11. GTIG attributes most of the added attacks to fast weaponization of disclosed n-days, so the exposure sits in the days after a patch ships.
Perspective Coverage
4 publishers
- Builder
- Builder 33%
- Operator
- Operator 61%
- Investor
- Investor 6%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+30
- Incentives35
- Confidence65
Google's Threat Intelligence Group counted 141 flaws exploited in the wild from January to August, while monthly disclosures doubled to 10,740. Patch teams do better sorting by that exploited set than by the total, though attackers now reach some public flaws within days.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence50
LiteLLM's MCP test endpoints let any valid proxy key run arbitrary commands on the gateway, rated CVSS 8.8. CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 8, 2026, confirming exploitation in the wild.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
Misha, who works on Gobare, found in public docs that OpenAI may delete a sandbox idle for an hour and Gobare pauses one after five minutes. Perplexity promises nothing between responses, so jobs that wait on a human or serve a preview have to fit one of those clocks.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives60
- Confidence50
A payments company is paying roughly 140 times annualised revenue for the switchboard that decides which model your code calls. The anti-lock-in pitch is now the lock-in.
Perspective Coverage
3 publishers
- Builder
- Builder 27%
- Operator
- Operator 23%
- Investor
- Investor 50%
Reality
- Evidence45
- Adoption62
- Hype gap+30
- Incentives55
- Confidence50
Two men arrested in Australia this week are alleged TeamPCP members. The AFP estimate filed alongside the case puts the worm's take at more than 500,000 credentials and 300GB of data, and that scale makes token lifetime the live question.
Perspective Coverage
17 publishers
- Builder
- Builder 33%
- Operator
- Operator 50%
- Investor
- Investor 17%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence62
SonicWall's CVSS 10.0 SSRF chains into command execution on remote access appliances, and JFrog Artifactory hands unauthenticated attackers admin under default configuration. Reverse shells and miners are already landing.
Perspective Coverage
13 publishers
- Builder
- Builder 24%
- Operator
- Operator 63%
- Investor
- Investor 13%
Reality
- Evidence72
- Adoption30
- Hype gap+15
- Incentives55
- Confidence68
LLM moderation queues need at most one current classification per accepted report, stored under a unique key before the queue ack, a dev.to guide argues. It plans for timeouts, lost leases and racing workers, and keeps unclassified reports visibly pending so a replay can still find them.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence35
Wiz found 294 of 3,074 internet-facing LiteLLM gateways answering admin requests in February, and two thirds of those had no key set at all rather than the documented sk-1234. That changes what needs fixing.
Reality
- Evidence62
- Adoption58
- Hype gap+25
- Incentives55
- Confidence64
Austin Larsen of Google's threat intelligence group says a Mandiant persona sat in TeamPCP's inner circle from almost the start of the campaign. For the companies the group breached, that infiltration was the warning system.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence55
A dev.to guide to GPT-5.6 pricing shows batch halving both token rates and a cheap-first cascade saving money until 9 in 10 calls escalate. Batch is opt-in and caching fails silently on short prefixes, so the default request often pays list price.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+15
- Incentives75
- Confidence50
CISA's exploited-vulnerability catalog now holds entries for LiteLLM, Kestra and Starlette, according to a dev.to writeup, and the quickstart docs for those tools still keep provider API keys in the process environment an attacker reads first.
Reality
- Evidence28
- Adoption
- Insufficient
- Hype gap+42
- Incentives32
- Confidence34
TeamPCP hijacked developer accounts, poisoned hundreds of programs and released a worm to automate the spread. Google says the inside access let it warn victims, revoke stolen credentials and help patch an AI-developed zero-day.
Reality
- Evidence32
- Adoption38
- Hype gap+22
- Incentives68
- Confidence30
LiteLLM works as a drop-in OpenAI replacement for teams running their own clusters, while managed gateways suit teams renting inference. OpenRouter's reported $113M round at a $1.3B valuation funds the rented side.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+20
- Incentives70
- Confidence35
A single September 2026 KEV batch produced 1,262,273 GitLab matches and nothing at all for Cisco Secure Firewall Management Center, because the console holding one of the two 10.0 bugs is the one passive scanning cannot fingerprint.
Reality
- Evidence45
- Adoption55
- Hype gap+10
- Incentives70
- Confidence50
A dev.to writeup pits Bifrost against LiteLLM on a shared four-core VPS, using the harness the Bifrost team maintains. The widest gap it reports traces back to a worker default the official LiteLLM image leaves unset.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+18
- Incentives68
- Confidence55
Earlier coverage
- An OpenAI evaluation model broke out of its sandbox through a flaw it found in its own package proxy
Security · September 17, 2026 · 1 publisher
- LiteLLM's MCP endpoint answered a failed key check with an empty auth object
Build · September 16, 2026 · 1 publisher
- One slash in a Host header moves the path Starlette's middleware checks
Build · September 16, 2026 · 1 publisher
- A $14.34 router matched Opus-5's score on LiteLLM's 21-task benchmark
Invest · September 15, 2026 · 1 publisher
- Whoever implements the server half of Responses picks your retrieval and veto defaults
Build · September 15, 2026 · 1 publisher
- Mohdel 1.0 computes per-call cost from a price catalog you maintain yourself
Build · September 11, 2026 · 1 publisher
- Uber halved the cost of an AI session by routing work away from frontier models
Leadership · September 11, 2026 · 1 publisher
- Uber's AI cost per session fell 18 points further than its cost per request
Build · September 10, 2026 · 1 publisher
- MCP's shipped auth extension buys the agent's token with an employee's browser login
Build · September 8, 2026 · 1 publisher
- Google traces a six-hour credential harvest to a coding chatbot running markdown playbooks
Product · September 8, 2026 · 1 publisher
- A backdoored LiteLLM package cleared 119,000 downloads before PyPI quarantined it
Build · September 5, 2026 · 1 publisher
- A query string smuggled into the Host header makes Starlette skip authentication
Build · September 4, 2026 · 1 publisher
- Malicious litellm PyPI releases tied to Trivy scan dependency bypassed official CI/CD
Security · September 3, 2026 · 1 publisher
- AFP charges two men near Perth over the self-spreading worm behind the TeamPCP compromises
Security · August 28, 2026 · 1 publisher
- CISA's exploited-vulnerability catalog now reaches the LLM gateway
Build · September 2, 2026 · 1 publisher
- A free Artifactory plugin can hold npm and PyPI versions until they age in public
Security · September 2, 2026 · 1 publisher
- Move AI guardrails into the gateway before every service ships its own copy
Build · September 2, 2026 · 1 publisher
- The compatibility probe wore the one User-Agent the CDN rule allowed
Build · August 31, 2026 · 1 publisher
- Every one of thirteen named 2025-26 incidents ran on a credential that still worked
Build · August 31, 2026 · 1 publisher
- Jackal IV's 58 arrests cover under a third of the suspects INTERPOL identified
Security · August 28, 2026 · 1 publisher
- TeamPCP hid its infostealer inside the scanners that audit everyone else's code
Science · August 28, 2026 · 1 publisher
- Exposed AI tooling now outnumbers exposed ICS hosts by more than two to one
Security · August 28, 2026 · 1 publisher
- Someone enumerated LiteLLM's key tables 36 hours after the advisory hit defender feeds
Security · August 28, 2026 · 1 publisher
- A backdoored litellm release turns every CI job that installed it into a credential incident
Science · August 28, 2026 · 1 publisher
- Oligo dates the crew behind ShadowRay 2.0's self-propagating botnet back to 2020
Security · August 28, 2026 · 1 publisher
- Experiential Labs bets its open-source router's traces will train cheaper replacements for rented models
Build · August 27, 2026 · 1 publisher
- An exposed LiteLLM gateway hands over every key in PID 1's environment
Build · August 27, 2026 · 1 publisher
- Attackers hid a cryptominer inside a LiteLLM MCP config test that reported success
Security · August 27, 2026 · 1 publisher
- Microsoft's own incident data says the AI gateway is now the credential store
Security · August 26, 2026 · 1 publisher
- The 97% saving was an agent failing quietly: token metrics need a completion gate
Build · August 25, 2026 · 1 publisher
- 56 build-pipeline attacks, one vendor's alert queue, and the February jump nobody can attribute yet
Build · August 23, 2026 · 1 publisher
- LiteLLM 1.82.7 and 1.82.8 shipped an infostealer: rotate everything those machines touched
Science · August 20, 2026 · 1 publisher
- LiteLLM's 40 minutes on PyPI: 153GB of loot, 2,488 named orgs, and the victims nobody can name
Science · August 19, 2026 · 1 publisher
- OX Security says MCP command execution is a design choice, so server owners own the risk
Science · August 19, 2026 · 1 publisher
- Ornith-1.0's benchmarks are fine. Ollama can't parse its tool calls.
Build · August 18, 2026 · 1 publisher
- VECT 2.0 shreds anything over 128 KB, which makes paying its ransom pointless
Leadership · August 18, 2026 · 1 publisher
- A 12MB Go binary bets agent cost control is cache stickiness, not a dashboard
Build · August 18, 2026 · 1 publisher
- Zalando's durable agentic engineering win was a proxy, not a model
Build · August 17, 2026 · 1 publisher
- The agent stack's attack surface is trust: pin the deps, audit the MCP servers
Build · August 16, 2026 · 1 publisher
- The 2,500-org compromise was a Trivy problem. LiteLLM was the closing act.
Security · August 14, 2026 · 1 publisher