High
Actively Exploited
cisa_kev
·
CVE-2026-42271
BerriAI LiteLLM Command Injection Vulnerability
Published Jun 8, 2026
CVSS 8.7
BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.
Affected AI Products
litellm