BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

AI Gateway Flaw Exploited, Added to US List

Critical LiteLLM flaw exploited, allows unauthenticated remote code execution and credential theft.

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a severe command injection flaw in BerriAI‘s LiteLLM software to its Known Exploited Vulnerabilities catalog.
  • The vulnerability, CVE-2026-42271, allows authenticated users to execute arbitrary commands and has been chained with another bug for unauthenticated remote code execution.
  • Successful exploitation could let attackers steal API keys, access model provider credentials, and compromise downstream AI infrastructure.
  • Users are urged to update to LiteLLM version 1.83.7 or later and Starlette to version 1.0.1 immediately.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical vulnerability in the widely-used BerriAI LiteLLM AI gateway to its catalog on June 9, 2026, citing active exploitation. This high-severity flaw allows attackers to run arbitrary commands on affected hosts, posing a significant threat to AI infrastructure security.

- Advertisement -

Tracked as CVE-2026-42271, the command injection vulnerability earned a CVSS score of 8.7. According to a description by BerriAI, two specific endpoints accepted unsafe configuration data that spawned subprocesses. Consequently, any user with a valid proxy API key could execute commands on the system.

The maintainers have since patched the issue in version 1.83.7. However, researchers at Horizon3.ai revealed the flaw can be combined with CVE-2026-48710, a host header validation bypass in the Starlette framework. This exploit chain, detailed last week, completely bypasses authentication for remote code execution.

Successful weaponization grants attackers extensive control over the compromised system. They could access stored credentials, siphon API keys, and move laterally into connected AI infrastructure. The combined CVSS score for this chained attack is a critical 10.0.

Mitigations include blocking the vulnerable endpoints at the network layer and rotating all proxy-stored credentials. Meanwhile, organizations must also review logs for unusual Host header activity. This incident follows another critical LiteLLM flaw, CVE-2026-42208, which was exploited within 36 hours of disclosure just over a month ago.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Crypto Groups Urge Senate To Pass CLARITY Act

Over 200 crypto firms urge U.S. Senate to pass the CLARITY Act before a...

Micron Soars on AI Demand, Gets Bullish $1,500 Price Target

Micron stock (MU) surged 170% in 2026 and hit an all-time high of $1,079.57...

Humanity Protocol Hacked: $30M Lost, Token Crashes 85%

Humanity Protocol, a decentralized identity project, lost over $30 million in a private key...

Tokenized Assets Shine Amid 2026 Crypto Slump

The market for tokenized real-world assets grew 589% from early 2025 to June 2026,...

Linux Kernel Flaw Lets Attackers Escalate to Root

A critical Linux kernel vulnerability (CVE-2026-23111) allows local attackers to gain root access and...

Must Read

What Are Anonymous Debit Cards And How Do They Work?

You've heard about anonymous debit cards, but what are they really? Anonymous Debit Cards are cards that let you make purchases without revealing your...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading