#vulns.comcp

← CVE intelligence

CVE-2026-42271 — BerriAI LiteLLM Command Injection Vulnerability

BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.

Severity
critical
Product
BerriAI LiteLLM
Published
2026-06-08
EPSS
0.836
CISA KEV
Known exploited
Ransomware
Known campaign use

References and validation

Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.