PoC public LiteLLM ai-ml LiteLLM (BerriAI maintainer) rce
LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers
CVE Tools coverage
Researchers at Obsidian Security report a multi-step vulnerability chain in LiteLLM that can allow a default low-privilege account to escalate to full proxy admin and achieve code execution. The affected issues are tracked as CVE-2026-47101, CVE-2026-47102, and CVE-2026-40217; together they can bypass authorization, elevate privileges, and escape the Custom Code Guardrail’s sandbox. Because LiteLLM sits in the middle of AI requests, a takeover can expose provider keys and sensitive traffic and can also let attackers tamper with prompts/responses processed by downstream agents. BerriAI’s fix is included starting with LiteLLM v1.83.14-stable—upgrade to that release or later to mitigate.