Feeds2.Feedburner Critical Unauthenticated RCE Vulnerability in LiteLLM Exploited in the Wild
Article Content
- •CVE-2026-42271 allows unauthenticated RCE when combined with CVE-2026-48710.
- •CISA added CVE-2026-42271 to its Known Exploited Vulnerabilities catalog on 2026-06-08.
- •Affected LiteLLM versions range from 1.74.2 to 1.83.6; patch available in version 1.83.7.
A critical command injection vulnerability, CVE-2026-42271, in LiteLLM, an open-source AI gateway, allows unauthenticated remote code execution (RCE) when chained with CVE-2026-48710, a Host header validation bypass in Starlette. This exploit affects LiteLLM versions 1.74.2 to 1.83.6, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) adding it to its Known Exploited Vulnerabilities catalog on 2026-06-08. Attackers can execute arbitrary commands on the host system without authentication, posing severe risks to AI infrastructures. The vulnerability was first disclosed on 2026-05-08, with public proof-of-concept code available since 2026-05-20. The attack surface is particularly attractive to cybercriminals targeting sensitive model provider credentials. Organizations are urged to upgrade to LiteLLM version 1.83.7 and Starlette version 1.0.1 to mitigate the risk.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (17)
Following this threat?
Track CVE-2026-42271 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
AI-Discovered Vulnerabilities Surge, Increasing RCE Threats Google's Threat Intelligence Group (GTIG) reports that software vulnerability disclosures doubled from 5,045 in January 2026 to 10,740 in August 2026, largely influenced by AI-assisted discovery. Notably, 50% of AI-discovered vulnerabilities enable remote code execution (RCE), compared to 26% of non-AI…