BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.
[POC] CVE-2026-42271 — CVE-2026-42271
CVE-2026-42271 - Draft
[POC] CVE-2026-42271 — CVE-2026-42271-PoC
The code for personally reproducing the corresponding vulnerability
PoC: CVE-2026-42271-LiteLLM-RCE
CVE-2026-42271 - LiteLLM AI Gateway MCP Command Injection RCE - PoC & Analysis | CVSS 8.8 | AMN SECURITY
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free