LiteLLM: LiteLLM: Arbitrary Code Execution via bytecode rewriting
Published Apr 10, 2026
7.5
HIGHCVSS 4.0
EPSS 3.40%
Description
LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.
Affected products
-
- Version bb0639701796218a3447160e55c0f1097446e4e6085df7dfd39f476d4143743fStatusaffectedConstraints-
- Version
No data.
Red Hat Ansible Automation Platform 2.6
ansible-automation-platform-26/lightspeed-chatbot-rhel9:1780102732
Fixed · RHSA-2026:24866
Red Hat OpenShift AI 3.3
rhoai/odh-llama-stack-core-rhel9:1782310008
Fixed · RHSA-2026:30056
Lightspeed Core
redhat-user-workloads/lightspeed-stack
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mlflow-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Automation Platform 2.6 | ansible-automation-platform-26/lightspeed-chatbot-rhel9:1780102732 | Fixed | RHSA-2026:24866 |
| Red Hat OpenShift AI 3.3 | rhoai/odh-llama-stack-core-rhel9:1782310008 | Fixed | RHSA-2026:30056 |
| Lightspeed Core | redhat-user-workloads/lightspeed-stack | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mlflow-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Apr 14, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Apr–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (5 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.40% (0.03399) | 88.45th | v5 (v2026.06.15) |
| Aug 25, 2026 | 15.06% (0.15056) | 96.46th | v5 (v2026.06.15) |
| Jul 1, 2026 | 6.50% (0.06496) | 92.93th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.71% (0.00709) | 48.47th | v5 (v2026.06.15) |
| Apr 11, 2026 | 0.19% (0.00188) | 40.73th | v4 (v2025.03.14) |
References (11)
- https://access.redhat.com/errata/RHSA-2026:24866
- https://access.redhat.com/errata/RHSA-2026:30056
- https://access.redhat.com/security/cve/CVE-2026-40217 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2457301 Issue Tracking
- https://github.com/BerriAI/litellm/releases/tag/v1.83.10-stable
- https://github.com/BerriAI/litellm/security/advisories/GHSA-wxxx-gvqv-xp7p
- https://github.com/advisories/GHSA-wxxx-gvqv-xp7p Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-40217
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40217.json
- https://www.cve.org/CVERecord?id=CVE-2026-40217
- https://www.x41-dsec.de/lab/advisories/x41-2026-001-litellm ExploitMitigationThird Party Advisory
Change history (0)
No recorded changes yet.