Critical Unauthenticated RCE Vulnerability in LiteLLM Exploited in the Wild

Critical Unauthenticated RCE Vulnerability in LiteLLM Exploited in the Wild

First seen 9 Jun 2026, 12:54 UTC CybersecuritynewsFeeds2.FeedburnerGbhackersLetsdatascienceRescana+10 86% similarity 86.0

Article Content

Browse articles
ThreatCluster

A critical command injection vulnerability, CVE-2026-42271, in LiteLLM, an open-source AI gateway, allows unauthenticated remote code execution (RCE) when chained with CVE-2026-48710, a Host header validation bypass in Starlette. This exploit affects LiteLLM versions 1.74.2 to 1.83.6, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) adding it to its Known Exploited Vulnerabilities catalog on 2026-06-08. Attackers can execute arbitrary commands on the host system without authentication, posing severe risks to AI infrastructures. The vulnerability was first disclosed on 2026-05-08, with public proof-of-concept code available since 2026-05-20. The attack surface is particularly attractive to cybercriminals targeting sensitive model provider credentials. Organizations are urged to upgrade to LiteLLM version 1.83.7 and Starlette version 1.0.1 to mitigate the risk.

Key Points: • CVE-2026-42271 allows unauthenticated RCE when combined with CVE-2026-48710. • CISA added CVE-2026-42271 to its Known Exploited Vulnerabilities catalog on 2026-06-08. • Affected LiteLLM versions range from 1.74.2 to 1.83.6; patch available in version 1.83.7.

ThreatCluster AI

Timeline

2026-05-08
CVE-2026-42271 published
A command injection vulnerability in LiteLLM was disclosed, affecting versions 1.74.2 to 1.83.6.
Rescana
2026-05-20
First public PoC released
Public proof-of-concept code for CVE-2026-42271 became available, facilitating exploitation.
Rescana
2026-05-26
CVE-2026-48710 published
A Host header validation bypass vulnerability in Starlette was disclosed, enabling exploitation of LiteLLM.
Rescana
2026-06-08
CISA adds CVE-2026-42271 to KEV
CISA confirmed active exploitation of CVE-2026-42271 and added it to the Known Exploited Vulnerabilities catalog.
Letsdatascience
2026-06-09
Patches released
LiteLLM version 1.83.7 was released to address the vulnerabilities, restricting access to critical endpoints.
Rescana

Community

Browse all →