Vulnerabilities · 134 days ago

Starlette Bug Exposes AI Agents’ Stored Credentials

A single Host header trick can slip past Starlette’s path-based authorization and turn trusted AI and app integrations into a credential leak. In FastAPI and the Python tooling built on Starlette, that means an attacker can reach protected endpoints and pull third-party account secrets instead of just poking one server.

The flaw is CVE-2026-48710, BadHost, and it affects Starlette versions prior to 1.0.1. Ars Technica says the blast radius runs through FastAPI and into vLLM, LiteLLM, Text Generation Inference, OpenAI-shim proxies, MCP servers, agent harnesses, eval dashboards, and model-management UIs, where stored email, calendar, database, and SaaS credentials can be exposed.

For teams running MCP-connected services, patching the framework fixes the entry point but does not undo any secrets already reached through it. The risk is account takeover through trusted integrations, not a single compromised host.

CVE-2026-48710

NVD KEV

Known exploited · CISA KEV

CVSS 6.5 MEDIUM: starlette is a lightweight ASGI framework/toolkit.

CISA federal remediation date Sep 16

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-05-27

Editions

Related stories