logo

LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE

ID: 0cb80d5e-88cd-55fc-9342-871b2a6327da

STIX ID: report--0cb80d5e-88cd-55fc-9342-871b2a6327da

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: [email protected] (The Hacker News)

...
...

CISA added CVE-2026-42271 — a command-injection flaw in BerriAI LiteLLM (CVSS 8.7) — to its Known Exploited Vulnerabilities catalog after evidence of active exploitation; when combined with a Starlette host-header validation bypass (CVE-2026-48710, combined CVSS 10.0) the chain enables unauthenticated remote code execution. Attackers exploiting the chain could execute arbitrary commands, steal model/provider credentials and API keys, and move laterally; affected users are advised to upgrade LiteLLM to ≥1.83.7 and Starlette to ≥1.0.1 or apply recommended mitigations (block vulnerable endpoints, restrict network access, rotate stored credentials, and review logs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.