PT-2026-31920 · Litellm · Litellm

·

CVE-2026-40217

·

Published

2026-02-19

·

Updated

2026-07-21

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LiteLLM versions through 2026-04-08
Description LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test custom code URI.
Recommendations Update LiteLLM to a version later than 2026-04-08.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08668
CLEANSTART-2026-AZ09261
CLEANSTART-2026-HP19968
CLEANSTART-2026-IR98353
CLEANSTART-2026-MR94452
CLEANSTART-2026-NL78203
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CVE-2026-40217
ECHO-C6D4-CF5F-A050
GHSA-3926-2JVF-FG29
GHSA-WXXX-GVQV-XP7P
PYSEC-2026-2601

Affected Products

Litellm