www.cisa.gov 6/9/2026, 1:48:44 AM · external

CISA warns of LiteLLM command injection flaw CVE-2026-42271

CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Listed in KEV
Patch Patch Available

THE Known Exploited Vulnerabilities (KEV) Catalog, maintained by CISA, serves as an authoritative resource for managing and prioritizing vulnerabilities that have been actively exploited. Organizations are encouraged to integrate the KEV catalog into their cybersecurity frameworks. The page highlights a specific vulnerability (CVE-2026-42271) related to the BerriAI LiteLLM, which allows command injection and poses risks even to users with low privilege.

Users are advised to implement vendor-recommended mitigations or discontinue use of the affected product. Additional resources are provided, including data formats for the catalog and a nomination link for new vulnerabilities.

View Primary Source Via www.cisa.gov

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline