Remote Code Execution Vulnerability in LiteLLM by X41 DSec
CVE-2026-40217

8.8HIGH

Key Information:

Vendor

Berriai

Status
Vendor
CVE Published:
10 April 2026

What is CVE-2026-40217?

CVE-2026-40217 is a serious vulnerability found in LiteLLM, a product developed by Berriai that serves as a machine learning model management system. Specifically, this vulnerability allows for remote code execution through exploitation of the bytecode rewriting feature at a designated URI. An attacker can leverage this vulnerability to run arbitrary code on the server, which poses a major risk to the integrity and confidentiality of the systems utilizing LiteLLM. Organizations that implement LiteLLM in their infrastructure may face severe operational disruptions or data integrity issues if the vulnerability is exploited.

Potential Impact of CVE-2026-40217

  1. Unauthorized Code Execution: The primary impact is the ability for adversaries to execute arbitrary code remotely. This could lead to unauthorized access and control over sensitive data, enabling the attacker to take complete command of the affected systems.

  2. System Compromise and Data Breach: Successful exploitation may result in significant data breaches, where confidential organizational data could be accessed, stolen, or compromised. This could lead to loss of intellectual property, customer data, and other sensitive information.

  3. Operational Disruption: Organizations may face severe disruptions in services and operations due to system outages or the need for extensive remediation efforts. This can lead to costly downtimes and harm the organization’s reputation, especially if customer data is involved.

Affected Version(s)

LiteLLM bb0639701796218a3447160e55c0f1097446e4e6085df7dfd39f476d4143743f

References

EPSS Score

15% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.