LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.
References
| Link | Resource |
|---|---|
| https://www.x41-dsec.de/lab/advisories/x41-2026-001-litellm/ | Third Party Advisory Exploit Mitigation |
Configurations
History
27 Apr 2026, 23:00
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:* | |
| References | () https://www.x41-dsec.de/lab/advisories/x41-2026-001-litellm/ - Third Party Advisory, Exploit, Mitigation | |
| First Time |
Litellm litellm
Litellm |
10 Apr 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-10 14:16
Updated : 2026-04-27 23:00
NVD link : CVE-2026-40217
Mitre link : CVE-2026-40217
CVE.ORG link : CVE-2026-40217
JSON object : View
Products Affected
litellm
- litellm
CWE
CWE-420
Unprotected Alternate Channel
