logo

LiteLLM vulnerability under active attack, CISA warns (CVE-2026-42271)

ID: 7f2e3ab0-e902-50b1-9113-5e7c21dda618

STIX ID: report--7f2e3ab0-e902-50b1-9113-5e7c21dda618

Feed Name: Help Net Security

Threat Score
80/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: Zeljka Zorz

...
...

A command-injection vulnerability (CVE-2026-42271) in BerryAI's LiteLLM gateway is being exploited in the wild and was added to CISA's Known Exploited Vulnerabilities catalog; a separate Starlette auth-bypass (CVE-2026-48710, “BadHost”) can remove the requirement for a valid proxy API key, enabling remote command execution, credential theft, and lateral movement. Fixes are available in LiteLLM v1.83.7 and Starlette v1.0.1; users are advised to upgrade, block vulnerable endpoints, restrict network access, and rotate stored credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.