CPE
Security Bypass Vulnerability in TIBCO JasperReports
1 TTP 1 CVEA vulnerability, CVE-2024-5225, in TIBCO JasperReports enables remote, unauthenticated attackers to bypass application-level security controls.
LiteLLM MCP Authentication Bypass via OAuth2 Passthrough Fallback
1 TTP 1 CVEAn authentication bypass vulnerability (CVE-2026-59822) exists in LiteLLM's MCP Streamable HTTP endpoint, affecting versions prior to 1.84.0, allowing an unauthenticated attacker to exploit a fallback path that replaces failed key validation with an empty authentication object, leading to the establishment of an authenticated MCP session using arbitrary Bearer tokens, enabling access to configured MCP tools and connected services.
LiteLLM Authenticated Command Injection via MCP stdio Test Endpoints (CVE-2026-42271)
2 rules 1 TTP 1 CVEA command injection vulnerability exists in LiteLLM versions 1.74.2 to < 1.83.7, allowing authenticated users with a valid API key to execute arbitrary OS commands as root via the MCP stdio transport through the `POST /mcp-rest/test/connection` and `POST /mcp-rest/test/tools/list` endpoints, especially in default Docker deployments, and a public exploit is available.