What is CVE-2026-42271?
CVE-2026-42271 is a command injection vulnerability in BerriAI LiteLLM that allows any authenticated user, including those with low-privilege internal-user keys, to execute arbitrary commands on the host system. Immediate network isolation of the affected instance is recommended, along with strict access controls until an official patch is applied.
Azərbaycanca: CVE-2026-42271 BerriAI LiteLLM-də command injection zəifliyidir. Bu boşluq qualifikasıyalı istənilən istifadəçi, o cümlədən aşağı səlahiyyətli daxili açar sahibləri tərəfindən host sistemində ixtiyari əmrlərin icra edilməsinə şərait yaradır. Dərhal təsirlənmiş sistemi şəbəkədən təcrid edin və rəsmi yamaq tətbiq olunana qədər istifadəçi girişlərini ciddi şəkildə məhdudlaşdırın.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
What product is affected by CVE-2026-42271?
CVE-2026-42271 is a command injection vulnerability found in BerriAI LiteLLM.
What privilege level does an attacker need to exploit CVE-2026-42271?
Any authenticated user, including those with low-privilege internal-user keys, can exploit the vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.