THREAT OPS › CVEs › CVE-2026-42271
CVE-2026-42271 — BerriAI LiteLLM Command Injection Vulnerability
BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.
Vulnerability details
- Affected productsLiteLLM
- KEV remediation due2026-06-22
Related reporting
- [CISA KEV] CVE-2026-48710 — Kludex Starlette: Kludex Starlette HTTP Request/Response Smuggling Vulnerabilitycisa_kev
- When AI infrastructure becomes the target: Securing gateways and control pointsmsstic
- When AI infrastructure becomes the target: Securing gateways and control pointsmsstic
- LiteLLM Supply Chain Attack: Inside the AI Breach That Exposed 2,500+ Companiessocradar_blog
- [CISA KEV] CVE-2026-42271 — BerriAI LiteLLM: BerriAI LiteLLM Command Injection Vulnerabilitycisa_kev
- June 2026 CVE Landscaperecordedfuture