news.mlab.sh
2 results
ransomware

LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE

A critical command injection vulnerability (CVE-2026-42271) in BerriAI’s LiteLLM has been actively exploited in the wild. The flaw, combined with a separate Starlette vulnerability (CVE-2026-48710), allows for unauthenticated remote code execution. Organizations using vulnerable versions of LiteLLM are advised to updat…

The Hacker News · Jun 9, 2026 Critical