Feeds2.Feedburner
Critical Unauthenticated RCE Vulnerability in LiteLLM Exploited in the Wild
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical command injection vulnerability, CVE-2026-42271, in LiteLLM, an open-source AI gateway, allows unauthenticated remote code execution (RCE) when chained with CVE-2026-48710, a Host header validation bypass in Starlette. This exploit affects LiteLLM versions 1.74.2 to 1.83.6, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) adding it to its Known Exploited Vulnerabilities catalog on 2026-06-08. Attackers can execute arbitrary commands on the host system without authentication, posing severe risks to AI infrastructures. The vulnerability was first disclosed on 2026-05-08, with public proof-of-concept code available since 2026-05-20. The attack surface is particularly attractive to cybercriminals targeting sensitive model provider credentials. Organizations are urged to upgrade to LiteLLM version 1.83.7 and Starlette version 1.0.1 to mitigate the risk.
Key Points: • CVE-2026-42271 allows unauthenticated RCE when combined with CVE-2026-48710. • CISA added CVE-2026-42271 to its Known Exploited Vulnerabilities catalog on 2026-06-08. • Affected LiteLLM versions range from 1.74.2 to 1.83.6; patch available in version 1.83.7.