Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-40217

Quick assessment

Affected
BerriAI LiteLLM
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

LiteLLM是Berri AI开源的一个应用程序。可以使用 OpenAI 格式调用所有 LLM API。 LiteLLM 2026-04-08及之前版本存在安全漏洞,该漏洞源于/guardrails/test_custom_code URI处允许通过字节码重写执行任意代码。

CVSS 8.8 · High EPSS 3.40% · P88

Public Exploits 1

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
BerriAI LiteLLM bb0639701796218a3447160e55c0f1097446e4e6085df7dfd39f476d4143743f affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-40217

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未保护的候选通道
Source: CVE Program / CVE List V5
Vulnerability Title
LiteLLM 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
LiteLLM是Berri AI开源的一个应用程序。可以使用 OpenAI 格式调用所有 LLM API。 LiteLLM 2026-04-08及之前版本存在安全漏洞,该漏洞源于/guardrails/test_custom_code URI处允许通过字节码重写执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
BerriAI LiteLLM bb0639701796218a3447160e55c0f1097446e4e6085df7dfd39f476d4143743f -

II. Public POCs for CVE-2026-40217

# POC Description Source Link Shenlong Link
1 LiteLLM before 1.25.0 allows authenticated users with the master API key to execute arbitrary Python code through the /guardrails/test_custom_code endpoint intended for custom guardrail testing. The endpoint’s insufficient filtering mechanisms can be bypassed, allowing attackers to abuse Python’s string operations and bytecode manipulation to break out of the restricted environment. Successful exploitation may lead to remote code execution as the LiteLLM process user, which may be root when using the default Docker image. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-40217.yaml POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-40217

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-40217 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-40217

No comments yet


Leave a comment