CVE-2026-40217Disclosure(litellm / litellm)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch litellm litellm systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-420CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • litellm

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 11 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 4 mentions (2026-04-10); latest day: 2
  • 11 total mentions across 7 days

Affected systems

Vendors
Products
litellm

Deep dive

Activity timeline11 mentions / 7d
01234Mentions · 2026-04-10: 4Mentions · 2026-06-16: 1Mentions · 2026-06-18: 1Mentions · 2026-08-11: 1Mentions · 2026-08-12: 1Mentions · 2026-08-24: 1Mentions · 2026-08-27: 2Active Exploitation · 2026-08-27: 2Patch / Workaround · 2026-06-16: 1Patch / Workaround · 2026-08-11: 1Technical Details · 2026-04-10: 4Technical Details · 2026-06-16: 1Technical Details · 2026-06-18: 1Technical Details · 2026-08-11: 1Technical Details · 2026-08-24: 104-1006-1606-1808-1108-1208-2408-27
Signal classification4 categories
Disclosure
654.5%
General
218.2%
Active Exploitation
218.2%
Exploit
19.1%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-104
Disclosure3General1
2026-06-161
Exploit1
2026-06-181
Disclosure1
2026-08-111
Disclosure1
2026-08-121
General1
2026-08-241
Disclosure1
2026-08-272
Active Exploitation2
Full discourse11 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-40217 - high 🚨 LiteLLM < 1.25.0 - Remote Code Execution > LiteLLM before 1.25.0 allows authenticated users with the master API key to execute a... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-40217 @pdnuclei #NucleiTemplates #cve

    Post summary

    The text announces a high‑severity Remote Code Execution vulnerability (CVE‑2026‑40217) in LiteLLM versions before 1.25.0, without referencing active exploitation, patches, or PoC details.

    00056464
    1.3K followersView on X
  • Miggo Security@MiggoSecurity
    Disclosure

    Attackers rarely need one devastating flaw. They need a sequence of small ones, each unlocking the next. CVE-2026-47101, CVE-2026-47102, CVE-2026-40217: a low-privilege token widened, access escalated to admin, code execution reaching the host. Two layers stopped it: ▪️WAF Copilot blocked the privilege escalation at the edge. ▪️The runtime sensor identified and blocked the code execution inside the app, before a CVE existed for it. Miggo Head of Architecture, Ben Stav, walks through the full chain, with equal parts technical rigor and few quirky memes. https://www.miggo.io/post/defense-in-depth-in-action-how-to-stop-the-litellm-chain-cve-2026-47101-cve-2026-47102-cve-2026-40217-with-panache

    Post summary

    The text announces a newly disclosed chain of CVEs, details the technical progression, and highlights defensive mitigations.

    0002067
    142 followersView on X
  • Sentinel Analysis@SentinelAnalyse
    Active Exploitation

    Here's the uncomfortable part: while the EU writes rules, the middleware running your agents is the new attack surface. LiteLLM CVE-2026-40217 and CVE-2026-49468 are being exploited right now.

    Post summary

    The post asserts that LiteLLM CVE-2026-40217 and CVE-2026-49468 are currently being exploited in real‑world attacks, but it offers no technical details or mitigation guidance.

    1000050
    5 followersView on X
  • Davin Jackson@Djax_Alpha
    General

    Defense-in-Depth in Action: How to Stop the LiteLLM Chain (CVE-2026-47101, CVE-2026-47102, CVE-2026-40217) with Panache https://api.cyfluencer.com/s/defense-in-depth-in-action-how-to-stop-the-litellm-chain-cve-2026-47101-cve-2026-47102-cve-2026-40217-with-panache-28947/1

    Post summary

    The text references multiple CVEs and points to a link titled "How to Stop the LiteLLM Chain" with Panache, but it does not provide technical or exploit details, nor does it describe a PoC or active exploitation.

    00010289
    9.1K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    CVE‑2026‑40217 – LiteLLM bytecode‑rewrite RCE (High) 🤖: LiteLLM through 2026‑04‑08 allows remote attackers to execute arbitrary code via bytecode rewriting in the model‑serving layer, turning a malicious payload into server‑side execution. CVSS 8.8, published 2026‑04‑10. https://cvefind.com/CVE-2026-40217 #CVE202640217 #LiteLLM#RCE #AI #AppSec #ThreatIntel

    Post summary

    The text announces CVE‑2026‑40217, providing technical details of a high‑severity RCE in LiteLLM, without indicating any PoC, exploit tools, or active exploitation.

    1000034
    567 followersView on X
  • Sentinel Analysis@SentinelAnalyse
    Active Exploitation

    Here's the uncomfortable part: while the EU writes rules, the middleware running your agents is the new attack surface. LiteLLM CVE-2026-40217 and CVE-2026-49468 are being exploited right now.

    Post summary

    The text asserts that LiteLLM CVE-2026-40217 and CVE-2026-49468 are currently being exploited, with no evidence of PoC, exploit tool, or mitigation available.

    0000047
    5 followersView on X
  • NewsTongue@NewsTongueX
    Disclosure

    🔴 Four AI tools broke same way in two weeks: prompt injection, privilege escalation, path traversal Varonis disclosed SearchLeak (CVE-2026-42824) on June 15—a silent exfiltration chain in Microsoft 365 Copilot Enterprise Search. A crafted URL triggers Copilot to search a victim's mailbox and leak data through a Bing SSRF with no user interaction or warning. Four days earlier, Obsidian Security published three chained CVEs against LiteLLM: CVE-2026-47101 (authorization bypass), CVE-2026-47102 (privilege escalation to proxy admin), and CVE-2026-40217 (sandbox escape via exec()). Combined CVSS 9.9.

    Post summary

    The post announces Varonis SearchLeak (CVE-2026-42824) and a set of chained LiteLLM CVEs (CVE-2026-47101, CVE-2026-47102, CVE-2026-40217) with technical exploitation details, but no PoC, exploit, or patch information.

    0000087
    306 followersView on X
  • SecureChap@SecureChap
    Exploit

    LiteLLM's virtual-key endpoint accepts an allowed_routes array from any internal_user. CVE-2026-47101 stores ["/*"] without role validation, granting the key access to every path. CVE-2026-47102 uses the key to call /user/update and set user_role to "proxy_admin" on the same record. CVE-2026-40217 then runs arbitrary Python through the Custom Code Guardrail test page. The exec() environment restores __builtins__ despite the explicit omission, exposing open and os.system. The full chain reaches the master key, provider credentials, and all traffic. Fixed in v1.83.14-stable. A privilege boundary enforced only by the value of one field is not a boundary.

    Post summary

    The post outlines a chain of CVEs in LiteLLM that bypass role validation to achieve privilege escalation, provides detailed technical information, and notes that the issue is fixed in v1.83.14-stable.

    0000056
    157 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-40217: HIGH] LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.#cve,CVE-2026-40217,#cybersecurity https://cvefind.com/CVE-2026-40217

    Post summary

    The post announces CVE-2026-40217 as a high‑severity remote code execution flaw in LiteLLM caused by bytecode rewriting on a specific URI.

    0000062
    619 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40217 LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI. https://www.cve.org/CVERecord?id=CVE-2026-40217 ----- Traducción: CVE-2026-40217 LiteLLM hasta 2026-04-08 permit… http://infoflow.cloud`

    Post summary

    The text announces CVE‑2026‑40217 in LiteLLM, outlining a remote code execution vulnerability through bytecode rewriting, without providing PoC, exploitation tools, active attack evidence, or patches.

    0000038
    67 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40217 LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI. https://www.cve.org/CVERecord?id=CVE-2026-40217

    Post summary

    The text reports CVE‑2026‑40217 in LiteLLM, describing remote code execution via bytecode rewriting at a specific endpoint, but provides no information on PoC, exploitability, patches, or active use.

    00000317
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applitellmlitellm---

Explore more