CVE-2026-40217 PUBLISHED

Assigner: mitre
Reserved: 10.04.2026 Published: 10.04.2026 Updated: 10.04.2026

LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor BerriAI
Product LiteLLM
Versions Default: unknown
  • Version bb0639701796218a3447160e55c0f1097446e4e6085df7dfd39f476d4143743f is affected

References

Problem Types

  • CWE-420 Unprotected Alternate Channel CWE