logo

Critical Unauthenticated RCE Vulnerability in LiteLLM Exploited in the Wild

ID: f0f2a074-a315-594c-b409-15d463c9b9bb

STIX ID: report--f0f2a074-a315-594c-b409-15d463c9b9bb

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-06-09

Date Updated: 2026-06-10

...
...

A critical command-injection vulnerability in LiteLLM (CVE-2026-42271), when combined with a Host header validation bypass in Starlette (CVE-2026-48710), allows unauthenticated remote code execution; the flaw affects LiteLLM 1.74.2–1.83.6, is being actively exploited in the wild, was added to CISA's KEV on 2026-06-08, and mitigations include upgrading LiteLLM to 1.83.7 and Starlette to 1.0.1 and monitoring for anomalous Host headers and subprocess activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.