$ intel.mask2.ca

ADVISORY · 2026-06-11 · SRC CISA-KEV · HIGH
2026-06-11 high REL 6/10

BerriAI LiteLLM Command Injection Allows Authenticated Users Arbitrary Code Execution

post-secondarygovernmentgeneral

BerriAI’s LiteLLM product contains a command injection flaw that permits any authenticated user with low-privilege credentials to execute arbitrary commands on affected systems. Organizations using this LLM interface layer should apply vendor patches or discontinue use if mitigations are unavailable. The vulnerability poses risk to confidentiality, integrity, and availability of systems where LiteLLM is deployed.

Why it matters in Western Canada: Post-secondary institutions, research organizations, and tech-forward public sector agencies in Western Canada using LiteLLM for AI/ML workloads on cloud infrastructure should inventory their deployments and apply patches by the June 2026 deadline to prevent insider threat escalation.

CVEs: CVE-2026-42271


Summary generated from the original advisory. Read the full source: cisa-kev

Source
https://nvd.nist.gov/vuln/detail/CVE-2026-42271
CVEs
CVE-2026-42271
Tags
litellm, command-injection, authentication-bypass, cloud-services, arbitrary-code-execution
Provenance
mask2-ti-pipeline (AI-assisted, human-reviewable)