Critical Unauthenticated RCE Vulnerability in LiteLLM Exploited in the Wild
ID: f0f2a074-a315-594c-b409-15d463c9b9bb
STIX ID: report--f0f2a074-a315-594c-b409-15d463c9b9bb
Feed Name: ThreatCluster
Threat Score
A critical command-injection vulnerability in LiteLLM (CVE-2026-42271), when combined with a Host header validation bypass in Starlette (CVE-2026-48710), allows unauthenticated remote code execution; the flaw affects LiteLLM 1.74.2–1.83.6, is being actively exploited in the wild, was added to CISA's KEV on 2026-06-08, and mitigations include upgrading LiteLLM to 1.83.7 and Starlette to 1.0.1 and monitoring for anomalous Host headers and subprocess activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
